#VU107437 Buffer access with incorrect length value in Juniper Junos OS - CVE-2025-21591
Published: April 14, 2025
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to a crash the entire system.
The vulnerability exists due to buffer access with incorrect length value error in the jdhcpd daemon. A remote non-authenticated attacker can send a DHCP packet with a malformed DHCP option to cause jdhcp to crash creating a Denial of Service (DoS) condition.