8.7
CVE-2025-30660 - Junos OS: MX Series: Decapsulation of specific GRE packets leads to PFE reset
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to …
8.7
CVE-2025-30659 - Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traff…
An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for Secure Vector Routing (SVR) recei…
8.7
CVE-2025-30658 - Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause mem…
A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX platforms with Anti-Virus enabled, if a server sends specifi…
6.9
CVE-2025-30657 - Junos OS: Processing of a specific BGP update causes the SRRD process to crash
An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a specific BGP update message…
8.7
CVE-2025-30656 - Junos OS: MX Series, SRX Series: Processing of specific SIP INVITE messages by the SIP ALG will lea…
An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If the SIP ALG proces…
6.8
CVE-2025-30655 - Junos OS and Junos OS Evolved: A specific CLI command will cause an RPD crash when rib-sharding and…
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific "show bgp neighbor" CLI command is run, the rpd c…
6.8
CVE-2025-30654 - Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Through the execution of a specif…
6
CVE-2025-30653 - Junos OS and Junos OS Evolved: LSP flap in a specific MPLS scenario leads to rpd crash
An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).On all Junos OS and Junos OS Evolved platforms, when an MPLS Label-Switched Path (LSP) is con…
6.8
CVE-2025-30652 - Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configure…
An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). When asregex-optimized is configured and a specific "s…
8.7
CVE-2025-30651 - Junos OS and Junos OS Evolved: Receipt of a specific ICMPv6 packet causes a memory overrun leading …
A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a specific ICMPv6 packet to an interface with…