vulnerability

Juniper Junos OS: 2025-10 Security Bulletin: Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash (JSA103165) (CVE-2025-60004)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Oct 8, 2025
Added
Jan 27, 2026
Modified
Feb 12, 2026

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.This issue affects iBGP and eBGP, over IPv4 and IPv6.This issue affects:Junos OS:

Solution

juniper-junos-os-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.