CVE-2025-59962

CVSS 5.3 MediumEPSS 0.0%
  • CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Published: 2025-10-09T16:15:46.247

An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker’s control, to cause rpd to crash and restart, leading to a Denial of Service (DoS).

With BGP sharding enabled, triggering route resolution of an indirect next-hop (e.g., an IGP route change over which a BGP route gets resolved), may cause rpd to crash and restart. An attacker causing continuous IGP route churn, resulting in repeated route re-resolution, will increase the likelihood of triggering this issue, leading to a potentially extended DoS condition.

This issue affects:

Junos OS:

* all versions before 21.4R3-S6, 
* from 22.1 before 22.1R3-S6, 
* from 22.2 before 22.2R3-S3, 
* from 22.3 before 22.3R3-S3, 
* from 22.4 before 22.4R3, 
* from 23.2 before 23.2R2; 

Junos OS Evolved: 

* all versions before 22.3R3-S3-EVO, 
* from 22.4 before 22.4R3-EVO, 
* from 23.2 before 23.2R2-EVO.

Versions before Junos OS 21.3R1 and Junos OS Evolved 21.3R1-EVO are unaffected by this issue.

Related CVE by CWE

No related CWE found.

Top CVE for Vendor

No vendor taxonomy on this entry.

Recently Exploited Similar Vulnerabilities

No recent KEV-listed items for this vendor/product.

How to fix CVE-2025-59962

CVE-2025-59962 is a medium severity vulnerability affecting the affected product.

Description: An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker’s control, to cause rpd to crash and restart, leading to a Denial of Service (DoS). With BGP […]

Exploit Difficulty: MEDIUM
⏱️ Time to exploit: 1-4 hours
🛠️ Required skills: Intermediate security knowledge
💰 Public exploits: May be available

How to Fix:

1 Identify affected systems

- Check if you're running the affected product

2 Immediate actions

- Update to the latest patched version
- If patching is not immediately possible: restrict network exposure, apply least-privilege access

3 Verification

- Test the fix in a staging environment first
- Review logs for signs of exploitation
- Monitor for IOCs (Indicators of Compromise)

4 Long-term prevention

- Enable automatic security updates
- Set up vulnerability monitoring
- Review and harden security configurations

Exploit Difficulty Assessment

MEDIUM
⏱️ Time to Exploit: 1-4 hours
🛠️ Skills Required: Intermediate security knowledge
💰 Public Exploits: May be available

Vulnerability Timeline

Oct 09, 2025
Vulnerability Published

CVE details first published to NVD database

Nov 12, 2025
Imported to Database

Added to this CVE tracking system

Detection Rules & IOCs

No specific detection rules generated for this vulnerability type.

No vendor/product data available.