Security updates: Attackers can crash network devices with Junos OS

Network devices such as Juniper switches are vulnerable. There are several vulnerabilities in the Junos OS operating system.

listen Print view
An appliance connects many clients with cables through the cloud. You and a few clients burn.

(Image: Erstellt mit KI in Bing Image Creator durch heise online / dmk)

2 min. read

Juniper devices with Junos OS could be targeted by attackers due to security vulnerabilities. Security updates are available for download. So far there are no reports of ongoing attacks.

If BGP (Border Gateway Protocol) trace options are configured on devices, attackers can exploit a vulnerability (CVE-2025-21598"high") to cause the RPD service to crash. Attacks should be possible without authentication.

This also applies to the next vulnerability (CVE-2025-21599"high"). In this case, prepared IPv6 packets can lead to DoS states so that devices no longer function reliably. The remaining vulnerabilities are classified as"medium" threat level. Crashes can also occur here. Attackers can also gain unauthorized access to data.

Videos by heise

Juniper lists the Junos OS versions secured against this in the following warning messages. List sorted by threat level in descending order:

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.