CVE-2025-30660: Junos OS: MX Series: Decapsulation of specific GRE packets leads to PFE reset
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop.
When this issue occurs the following logs can be observed:
<fpc #> MQSS(0): LI-3: Received a parcel with more than 512B accompanying data CHASSISDFPCASICERROR: ASIC Error detected <...>
This issue affects Junos OS:
all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S4, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S2, 23.4 versions before 23.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30660?
CVE-2025-30660 has a high severity rating due to its potential to cause Denial-of-Service attacks.
How do I fix CVE-2025-30660?
To mitigate CVE-2025-30660, update your Junos OS to a version that addresses this vulnerability.
What systems are affected by CVE-2025-30660?
CVE-2025-30660 affects Juniper Networks Junos OS on MX Series devices running specific versions up to 23.4R2.
What type of attack does CVE-2025-30660 allow?
CVE-2025-30660 enables an unauthenticated, network-based attacker to execute Denial-of-Service attacks.
Is authentication required to exploit CVE-2025-30660?
No, CVE-2025-30660 can be exploited by unauthenticated attackers over the network.