#VU113052 Improper Handling of Length Parameter Inconsistency in Junos OS Evolved and Juniper Junos OS - CVE-2025-52949
Published: July 18, 2025
Junos OS Evolved
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of length parameter inconsistency error in the routing protocol daemon (rpd). A remote BGP peer can send a specifically malformed BGP packet and cause rpd to crash and restart, resulting in a Denial of Service (DoS).