« Volver al listado

CVE-2025-60004

Estado: AnalizadaAlta (8.7)—

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).

When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.

A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.

This issue affects iBGP and eBGP, over IPv4 and IPv6.

This issue affects: Junos OS: * 23.4 versions from

Leer descripción completaMostrar menos

24.2R2

Detalles técnicos trazas, registros y código del informe original
23.4R2-S3 before 23.4R2-S5,
  *  24.2 versions from

before 24.2R2-S1,
  *  24.4 versions before 24.4R1-S3, 24.4R2;

Junos OS Evolved:
  *  23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO,
  *  24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO,
  *  24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N/UI:N indica explotación remota sin autenticación (T1190). El impacto es DoS por crash del rpd mediante BGP EVPN malformado (T1499.004: aplicación).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-60004",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-60004",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-09T18:47:25.363001Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "YES",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "MODERATE",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "affected",
              "version": "23.4R2-S3",
              "lessThan": "23.4R2-S5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "24.2R2",
              "lessThan": "24.2R2-S1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "24.4R1",
              "lessThan": "24.4R1-S3, 24.4R2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS Evolved",
          "versions": [
            {
              "status": "affected",
              "version": "23.4R2-S2-EVO",
              "lessThan": "23.4R2-S5-EVO",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "24.2R2-EVO",
              "lessThan": "24.2R2-S1-EVO",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "24.4R1-EVO",
              "lessThan": "24.4R1-S3-EVO, 24.4R2-EVO",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-10-09T17:16:03.673",
  "references": [
    {
      "url": "https://supportportal.juniper.net/JSA103165",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).\n\nWhen an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.\n\nA BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.\n\nThis issue affects iBGP and eBGP, over IPv4 and IPv6.\n\n\nThis issue affects:\nJunos OS:\n  *  23.4 versions from \n\n23.4R2-S3 before 23.4R2-S5,\n  *  24.2 versions from \n\n24.2R2 \n\nbefore 24.2R2-S1,\n  *  24.4 versions before 24.4R1-S3, 24.4R2;\n\n\n\nJunos OS Evolved:\n  *  23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO,\n  *  24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO,\n  *  24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO."
    }
  ],
  "lastModified": "2026-06-17T09:49:11.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7C207E3-0252-4192-8E8C-E2ED2831B4F4"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6974492-FE69-4340-8881-61C3329C1545"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "266B520A-482A-43F7-90F8-B9D64D30034F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C452BDCB-34E3-42D3-8909-2312356EB70A"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B8158F2-2028-40E9-955F-CFD581A32F60"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A7233A1-EC7A-4458-9AE1-835480A03A21"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:24.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EEF1798-F3C2-4645-96E7-1E82368B184D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB2FE5FE-0ADE-406E-A23D-FDCC104B2496"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E58987A-D7B7-4FFF-9969-E8FD76AE2BE3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E779C0D4-A8F7-4976-B3C8-B9802B96E715"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "080BEA58-9667-4C2C-810D-DC1187DB67DA"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B32ADA05-5F5D-45B6-BB7B-3FA6A6F229F5"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6526E82-A6A6-4A65-9B01-B3FCB947F44E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF3B74FA-DF84-4E3E-BCF9-44EEF9E45910"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25DA0DD2-E974-448C-BD05-ED6FCA4725FB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}