CVE-2025-52981: Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on
SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3
allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If a sequence of specific PIM packets is received, this will cause a flowd crash and restart.
This issue affects Junos OS:
all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S11, 22.2 versions before 22.2R3-S7, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S4, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.
This is a similar, but different vulnerability than the issue reported as
CVE-2024-47503, published in JSA88133.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52981?
CVE-2025-52981 has been rated as a critical severity vulnerability due to its potential to cause a Denial of Service.
How do I fix CVE-2025-52981?
To fix CVE-2025-52981, you should upgrade your Junos OS to a version that addresses this vulnerability, such as 21.2R3-S10 or later.
Who is affected by CVE-2025-52981?
CVE-2025-52981 affects Juniper Networks Junos OS running on SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3.
What impact does CVE-2025-52981 have on systems?
CVE-2025-52981 allows an unauthenticated attacker to potentially cause a Denial of Service condition on affected systems.
Is there a workaround for CVE-2025-52981?
Currently, there are no recommended workarounds to mitigate CVE-2025-52981; applying updates is the suggested course of action.