Impact
A flaw in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to inject a specially malformed BGP update into an existing BGP session, causing the routing protocol daemon (RPD) to crash and restart. The crash occurs before the update is readvertised, so it does not spread downstream, but it brings the router offline until routing reconvergence, resulting in a network service outage.
Affected Systems
Vulnerable routers are those running Junos OS or Junos OS Evolved versions prior to 25.2R2 (Junos OS) or 25.2R2‑EVO (Junos OS Evolved). This includes all 25.2 releases, but not the earlier 25.2R1 or earlier releases. The flaw can affect any router that participates in BGP sessions with adjacent peers, regardless of the operating network tier.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, whereas the EPSS score of less than 1% reflects a very low exploitation probability in the current data set. The vulnerability is not listed in CISA’s KEV catalog, but because it leads to a router crash and outage, it remains a high‑priority concern for operators who require continuous BGP availability. The attack vector is likely adjacent, requiring an established BGP session with the target router. No workaround is available, so remediation must be performed through a software update.
OpenCVE Enrichment