CVE-2025-21598

CWE-125Out-of-bounds Read4 documents4 sources
Severity
8.2HIGH
EPSS
0.4%
top 36.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9

Description

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects: Junos OS: * from 21.2R3-S8 before 21.2R3-S9, * from 21.4R3-S7 before 21.4R3-S9, * from 22.2R3-S4 before 22.2R3-S5, * from 22.3R3-S2 before 22.3R3-S4, * from 22.4R3 before 22.4R3-S5, * from 23.2R2 befo

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Packages4 packages

CVEListV5juniper_networks/junos_os_evolved21.4R3-S7-EVO21.4R3-S9-EVO+6
CVEListV5juniper_networks/junos_os21.2R3-S821.2R3-S9+7
NVDjuniper/junos_os_evolved7 versions+6
NVDjuniper/junos8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-68jp-4r95-v8vr: An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, netwo2025-01-09
CVEList
Junos OS and Junos OS Evolved: When BGP traceoptions are configured, receipt of malformed BGP packets causes RPD to crash2025-01-09

📋Vendor Advisories

1
Juniper
CVE-2025-21598: An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, netwo2025-01-09
CVE-2025-21598 (HIGH CVSS 8.2) | An Out-of-bounds Read vulnerability | cvebase.io