PT-2025-15844 · Juniper Networks · Junos
Published
2025-04-09
·
Updated
2025-04-11
·
CVE-2025-21591
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Junos OS versions 23.1R1 through 23.2R2-S3
Junos OS versions 23.4 through 23.4R2-S3
Junos OS versions 24.2 through 24.2R2
Description:
A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to crash creating a Denial of Service (DoS) condition. Continuous receipt of these DHCP packets using the malformed DHCP Option will create a sustained Denial of Service (DoS) condition. There are no indicators of compromise for this issue.
Recommendations:
For versions 23.1R1 through 23.2R2-S3, update to version 23.2R2-S3 or later.
For versions 23.4 through 23.4R2-S3, update to version 23.4R2-S3 or later.
For versions 24.2 through 24.2R2, update to version 24.2R2 or later.
As a temporary workaround, consider disabling DHCP snooping until a patch is available. Restrict access to the jdhcpd daemon to minimize the risk of exploitation. Avoid using malformed DHCP options in the affected API endpoint until the issue is resolved.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos