CVE-2025-52953: Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denial of Service (DoS).
Continuous receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
This issue affects iBGP and eBGP and both IPv4 and IPv6 are affected by this vulnerability.
This issue affects Junos OS:
All versions before 21.2R3-S9, from 21.4 before 21.4R3-S11, from 22.2 before 22.2R3-S7, from 22.4 before 22.4R3-S7, from 23.2 before 23.2R2-S4, from 23.4 before 23.4R2-S4, from 24.2 before 24.2R2, from 24.4 before 24.4R1-S3, 24.4R2
Junos OS Evolved:
All versions before 22.2R3-S7-EVO, from 22.4-EVO before 22.4R3-S7-EVO, from 23.2-EVO before 23.2R2-S4-EVO, from 23.4-EVO before 23.4R2-S4-EVO, from 24.2-EVO before 24.2R2-EVO, from 24.4-EVO before 24.4R1-S3-EVO, 24.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52953?
CVE-2025-52953 has been rated as a high severity vulnerability due to its potential to cause Denial of Service.
How do I fix CVE-2025-52953?
To mitigate CVE-2025-52953, upgrade to an unaffected version of Junos OS or Junos OS Evolved as specified in Juniper's security advisory.
What impact does CVE-2025-52953 have on Junos OS?
CVE-2025-52953 can lead to a Denial of Service by allowing an unauthenticated attacker to reset BGP sessions.
Which versions of Junos OS are affected by CVE-2025-52953?
CVE-2025-52953 affects Junos OS versions up to 21.2R3-S9 and Junos OS Evolved versions up to 22.2R3-S7-EVO.
Can CVE-2025-52953 be exploited remotely?
Yes, CVE-2025-52953 can be exploited remotely by an unauthenticated adjacent attacker.