A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

When forwarding-options sampling is enabled, receipt of any traffic destined to the Routing Engine (RE) by the PFE line card leads to an FPC crash and restart, resulting in a Denial of Service (DoS).

Continued receipt and processing of any traffic leading to the RE by the PFE line card will create a sustained Denial of Service (DoS) condition to the PFE line card.


This issue affects Junos OS on SRX4700: 



* from 24.4 before 24.4R1-S3, 24.4R2


This issue affects IPv4 and IPv6.

Project Subscriptions

Vendors Products
Juniper Subscribe
Advisories

No advisories yet.

Fixes

Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 24.4R1-S3, 24.4R2, 25.2R1 and all subsequent releases.


Workaround

To workaround this issue an administrator must block all traffic from the PFE line card to the Routing Engine (RE) until a fix can be taken. Even while under a persistent DoS attack the RE will continue to be accessible to administrators through non-PFE line card interfaces E.g. Console, FXP0.

History

Fri, 23 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Juniper junos
CPEs cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r2:*:*:*:*:*:*
Vendors & Products Juniper junos

Fri, 10 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Juniper
Juniper junos Os
Juniper srx4700
Vendors & Products Juniper
Juniper junos Os
Juniper srx4700

Thu, 09 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
Description A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When forwarding-options sampling is enabled, receipt of any traffic destined to the Routing Engine (RE) by the PFE line card leads to an FPC crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of any traffic leading to the RE by the PFE line card will create a sustained Denial of Service (DoS) condition to the PFE line card. This issue affects Junos OS on SRX4700:  * from 24.4 before 24.4R1-S3, 24.4R2 This issue affects IPv4 and IPv6.
Title Junos OS: SRX4700: When forwarding-options sampling is enabled any traffic destined to the RE will cause the forwarding line card to crash and restart
Weaknesses CWE-908
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/V:C/RE:M/U:Green'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2025-10-09T19:00:04.954Z

Reserved: 2025-09-23T18:19:06.955Z

Link: CVE-2025-59964

cve-icon Vulnrichment

Updated: 2025-10-09T18:59:58.500Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-09T16:15:46.443

Modified: 2026-01-23T18:36:49.490

Link: CVE-2025-59964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-10T11:17:48Z

Weaknesses