vulnerability
Juniper Junos OS: 2025-10 Security Bulletin: Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash (JSA103165) (CVE-2025-60004)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Oct 8, 2025 | Jan 27, 2026 | Feb 12, 2026 |
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.This issue affects iBGP and eBGP, over IPv4 and IPv6.This issue affects:Junos OS:
Solution
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.