PT-2025-15857 · Juniper Networks · Junos

Published

2025-04-09

·

Updated

2025-04-11

·

CVE-2025-30649

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions: Junos OS versions prior to 22.2R3-S6 Junos OS versions from 22.4 before 22.4R3-S4 Junos OS versions from 23.2 before 23.2R2-S3 Junos OS versions from 23.4 before 23.4R2-S4 Junos OS versions from 24.2 before 24.2R1-S2, 24.2R2
Description: An Improper Input Validation issue in the syslog stream TCP transport of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to send specific spoofed packets, causing a CPU Denial of Service (DoS) to the MX-SPC3 SPUs. Continued receipt and processing of these packets will sustain the DoS condition. An indicator of compromise is a spike in SPC3 SPUs utilization, which can be checked using the command show services service-sets summary to look for high CPU usage.
Recommendations: For versions prior to 22.2R3-S6, update to 22.2R3-S6 or later. For versions from 22.4 before 22.4R3-S4, update to 22.4R3-S4 or later. For versions from 23.2 before 23.2R2-S3, update to 23.2R2-S3 or later. For versions from 23.4 before 23.4R2-S4, update to 23.4R2-S4 or later. For versions from 24.2 before 24.2R1-S2, 24.2R2, update to 24.2R1-S2 or later, or apply the 24.2R2 patch. As a temporary workaround, consider monitoring the CPU utilization of the SPC3 SPUs and restricting access to the syslog stream TCP transport to minimize the risk of exploitation.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-05198
CVE-2025-30649

Affected Products

Junos