CVE-2025-60004: Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).
When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.
A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.
This issue affects iBGP and eBGP, over IPv4 and IPv6.
This issue affects: Junos OS: 23.4 versions from
23.4R2-S3 before 23.4R2-S5, 24.2 versions from
24.2R2
before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;
Junos OS Evolved: 23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO, 24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO, 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60004?
CVE-2025-60004 is classified as a high severity vulnerability due to its potential to allow unauthenticated attackers to cause a Denial-Of-Service.
How do I fix CVE-2025-60004?
To fix CVE-2025-60004, upgrade your Junos OS or Junos OS Evolved to the latest recommended version provided by Juniper Networks.
Which versions are affected by CVE-2025-60004?
CVE-2025-60004 affects specific versions of Junos OS and Junos OS Evolved, including versions from 23.4R2-S3 to 23.4R2-S5 and 24.4R1 to 24.4R2, among others.
Is CVE-2025-60004 exploitable remotely?
Yes, CVE-2025-60004 is exploitable remotely as it allows unauthenticated, network-based attackers to initiate a Denial-Of-Service attack.
What kind of vulnerability is CVE-2025-60004?
CVE-2025-60004 is categorized as an Improper Check for Unusual or Exceptional Conditions vulnerability.