CVE-2025-59975: Junos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoS
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS).
After continuously flooding the system with inbound connection requests, all available file handles become consumed, blocking access to the system via SSH and the web user interface (WebUI), resulting in a management interface DoS. A manual reboot of the system is required to restore functionality.
This issue affects Junos Space: all versions before 22.2R1 Patch V3, from 23.1 before 23.1R1 Patch V3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59975?
CVE-2025-59975 is a high severity vulnerability that can lead to Denial of Service (DoS) due to resource exhaustion.
How do I fix CVE-2025-59975?
To fix CVE-2025-59975, update the Junos Space software to a patched version, ensuring it is above 22.2R1 Patch V3.
What type of attack does CVE-2025-59975 expose Junos Space to?
CVE-2025-59975 exposes Junos Space to Denial of Service (DoS) attacks by flooding the system with excessive API calls.
Can CVE-2025-59975 be exploited remotely?
Yes, CVE-2025-59975 can be exploited by unauthenticated network-based attackers.
What does CVE-2025-59975 affect in Junos Space?
CVE-2025-59975 affects the HTTP daemon (httpd) of Junos Space, leading to resource consumption issues.