CVE-2025-60004: Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash

Published Oct 9, 2025
·
Updated

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).

When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.

A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.

This issue affects iBGP and eBGP, over IPv4 and IPv6.

This issue affects: Junos OS: 23.4 versions from

23.4R2-S3 before 23.4R2-S5, 24.2 versions from

24.2R2

before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;

Junos OS Evolved: 23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO, 24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO, 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.

Affected Software

17 affected components
Juniper Networks Junos OS>=23.4R2-S3<23.4R2-S5, >=24.2R2<24.2R2-S1, <24.4R1-S3, <=24.4R2
Juniper Networks Junos OS Evolved>=23.4R2-S2-EVO<23.4R2-S5-EVO, >=24.2R2-EVO<24.2R2-S1-EVO, <24.4R1-S3-EVO, <=24.4R2-EVO
Juniper Junos=23.4-r2-s3
Juniper Junos=23.4-r2-s4
Juniper Junos=24.2-r2
Juniper Junos=24.4
Juniper Junos=24.4-r1
Juniper Junos=24.4-r1-s2
Juniper Junos=24.4-r2
Juniper Junos OS Evolved=23.4-r2-s2
Juniper Junos OS Evolved=23.4-r2-s3
Juniper Junos OS Evolved=23.4-r2-s4
Juniper Junos OS Evolved=24.2-r2
Juniper Junos OS Evolved=24.4
Juniper Junos OS Evolved=24.4-r1
Juniper Junos OS Evolved=24.4-r1-s2
Juniper Junos OS Evolved=24.4-r2

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 23.4R2-S5, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.

Event History

Oct 9, 2025
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-60004?

CVE-2025-60004 is classified as a high severity vulnerability due to its potential to allow unauthenticated attackers to cause a Denial-Of-Service.

2

How do I fix CVE-2025-60004?

To fix CVE-2025-60004, upgrade your Junos OS or Junos OS Evolved to the latest recommended version provided by Juniper Networks.

3

Which versions are affected by CVE-2025-60004?

CVE-2025-60004 affects specific versions of Junos OS and Junos OS Evolved, including versions from 23.4R2-S3 to 23.4R2-S5 and 24.4R1 to 24.4R2, among others.

4

Is CVE-2025-60004 exploitable remotely?

Yes, CVE-2025-60004 is exploitable remotely as it allows unauthenticated, network-based attackers to initiate a Denial-Of-Service attack.

5

What kind of vulnerability is CVE-2025-60004?

CVE-2025-60004 is categorized as an Improper Check for Unusual or Exceptional Conditions vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203