CVE-2025-59958: Junos OS Evolved: PTX Series: When a firewall filter rejects traffic these packets are erroneously sent to the RE
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability.
When an output firewall filter is configured with one or more terms where the action is 'reject', packets matching these terms are erroneously sent to the Routing Engine (RE) and further processed there. Processing of these packets will consume limited RE resources. Also responses from the RE back to the source of this traffic could reveal confidential information about the affected device. This issue only applies to firewall filters applied to WAN or revenue interfaces, so not the mgmt or lo0 interface of the routing-engine, nor any input filters.
This issue affects Junos OS Evolved on PTX Series:
all versions before 22.4R3-EVO, 23.2 versions before 23.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59958?
CVE-2025-59958 is considered a high-severity vulnerability that impacts the confidentiality and availability of affected systems.
How do I fix CVE-2025-59958?
To fix CVE-2025-59958, you should upgrade to a patched version of Juniper Networks Junos OS Evolved, beyond 23.2R2-EVO.
Which products are affected by CVE-2025-59958?
CVE-2025-59958 affects Juniper Networks Junos OS Evolved on PTX Series devices.
Can CVE-2025-59958 be exploited remotely?
Yes, CVE-2025-59958 can be exploited by an unauthenticated, network-based attacker.
What are the potential impacts of CVE-2025-59958?
The potential impacts of CVE-2025-59958 include disruption to service availability and compromise of sensitive information.