Loading HuntDB...

CVE-2025-21598

HIGH
Published 2025-01-09T18:16:32.549Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-21598. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
7.5
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.001
probability
of exploitation in the wild

There is a 0.1% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.252
Higher than 25.2% of all CVEs

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Description

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd.
This issue affects:

Junos OS: 

* from 21.2R3-S8 before 21.2R3-S9, 
* from 21.4R3-S7 before 21.4R3-S9, 
* from 22.2R3-S4 before 22.2R3-S5, 
* from 22.3R3-S2 before 22.3R3-S4, 
* from 22.4R3 before 22.4R3-S5, 
* from 23.2R2 before 23.2R2-S2, 
* from 23.4R1 before 23.4R2-S1, 
* from 24.2R1 before 24.2R1-S1, 24.2R2.

Junos OS Evolved:
* from 21.4R3-S7-EVO before 21.4R3-S9-EVO, 
* from 22.2R3-S4-EVO before 22.2R3-S5-EVO, 
* from 22.3R3-S2-EVO before 22.3R3-S4-EVO, 
* from 22.4R3-EVO before 22.4R3-S5-EVO, 
* from 23.2R2-EVO before 23.2R2-S2-EVO, 
* from 23.4R1-EVO before 23.4R2-S1-EVO, 
* from 24.2R1-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue requires a BGP session to be established.

This issue can propagate and multiply through multiple ASes until reaching vulnerable devices.

This issue affects iBGP and eBGP.

This issue affects IPv4 and IPv6.

An indicator of compromise may be the presence of malformed update messages in a neighboring AS which is unaffected by this issue:

For example, by issuing the command on the neighboring device:
 show log messages

Reviewing for similar messages from devices within proximity to each other may indicate this malformed packet is propagating:
  rpd[<pid>]: Received malformed update from <IP address> (External AS <AS#>)
and
  rpd[<pid>]: Malformed Attribute

Available Exploits

No exploits available for this CVE.

Related News

Unauthenticated Attackers Can Exploit Junos Vulnerabilities (CVE-2025-21598 & CVE-2025-21599)

Juniper Networks has released advisories detailing two significant vulnerabilities affecting their Junos OS and Junos OS Evolved systems. The post Unauthenticated Attackers Can Exploit Junos Vulnerabilities (CVE-2025-21598 & CVE-2025-21599) appeared first on Cybersecurity News.

SecurityOnline.info 2025-01-14 01:36

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-68jp-4r95-v8vr

Advisory Details

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects: Junos OS:  * from 21.2R3-S8 before 21.2R3-S9,  * from 21.4R3-S7 before 21.4R3-S9,  * from 22.2R3-S4 before 22.2R3-S5,  * from 22.3R3-S2 before 22.3R3-S4,  * from 22.4R3 before 22.4R3-S5,  * from 23.2R2 before 23.2R2-S2,  * from 23.4R1 before 23.4R2-S1,  * from 24.2R1 before 24.2R1-S1, 24.2R2. Junos OS Evolved: * from 21.4R3-S7-EVO before 21.4R3-S9-EVO,  * from 22.2R3-S4-EVO before 22.2R3-S5-EVO,  * from 22.3R3-S2-EVO before 22.3R3-S4-EVO,  * from 22.4R3-EVO before 22.4R3-S5-EVO,  * from 23.2R2-EVO before 23.2R2-S2-EVO,  * from 23.4R1-EVO before 23.4R2-S1-EVO,  * from 24.2R1-EVO before 24.2R1-S2-EVO, 24.2R2-EVO. This issue requires a BGP session to be established. This issue can propagate and multiply through multiple ASes until reaching vulnerable devices. This issue affects iBGP and eBGP. This issue affects IPv4 and IPv6. An indicator of compromise may be the presence of malformed update messages in a neighboring AS which is unaffected by this issue: For example, by issuing the command on the neighboring device:  show log messages Reviewing for similar messages from devices within proximity to each other may indicate this malformed packet is propagating:   rpd[<pid>]: Received malformed update from <IP address> (External AS <AS#>) and   rpd[<pid>]: Malformed Attribute

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Advisory provided by GitHub Security Advisory Database. Published: January 9, 2025, Modified: January 9, 2025

References

Published: 2025-01-09T18:16:32.549Z
Last Modified: 2025-01-09T20:15:00.238Z
Copied to clipboard!