Description

A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an established BGP session which contains a specific, valid, optional, transitive path attribute, rpd will crash and restart. This issue affects eBGP and iBGP over IPv4 and IPv6. This issue affects: Junos OS: * 22.1 versions from 22.1R1 before 22.2R3-S4, * 22.3 versions before 22.3R3-S3, * 22.4 versions before 22.4R3-S2, * 23.2 versions before 23.2R2, * 23.4 versions before 23.4R2.

INFO

Published Date :

2025-07-11T15:08:15.638Z

Last Modified :

2025-07-15T19:55:48.095Z

Source :

juniper
AFFECTED PRODUCTS

The following products are affected by CVE-2025-52980 vulnerability.

Vendors Products
Juniper
  • Junos
  • Srx300
  • Srx320
  • Srx340
  • Srx345
  • Srx380
Juniper Networks
  • Junos Os
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-52980.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact