CVE-2025-59959

CWE-8224 documents4 sources
Severity
6.8MEDIUM
EPSS
0.0%
top 99.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15

Description

An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route detail' is executed, and at least one of the routes in the intended output has specific attributes, this will cause an rpd crash and restart. 'show route ... extensive' is not affected. This issue affects: Junos OS: * all versions befor

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Packages4 packages

CVEListV5juniper_networks/junos_os_evolved23.223.2R2-S5-EVO+4
CVEListV5juniper_networks/junos_os23.223.2R2-S5+4
NVDjuniper/junos< 22.4+5

🔴Vulnerability Details

2
GHSA
GHSA-r929-9699-qx4q: An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local,2026-01-15
CVEList
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash2026-01-15

📋Vendor Advisories

1
Juniper
CVE-2025-59959: An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local,2026-01-15
CVE-2025-59959 (MEDIUM CVSS 6.8) | An Untrusted Pointer Dereference vu | cvebase.io