CVE-2025-52984
Severity CVSS v4.0:
HIGH
Type:
CWE-476
NULL Pointer Dereference
Publication date:
11/07/2025
Last modified:
11/07/2025
Description
A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device.<br />
<br />
When static route points to a reject next hop and a gNMI query is processed for that static route, rpd crashes and restarts.<br />
<br />
This issue affects:<br />
<br />
Junos OS: * all versions before 21.2R3-S9,<br />
* 21.4 versions before 21.4R3-S10, <br />
* 22.2 versions before 22.2R3-S6,<br />
* 22.4 versions before 22.4R3-S6,<br />
* 23.2 versions before 23.2R2-S3,<br />
* 23.4 versions before 23.4R2-S4,<br />
* 24.2 versions before 24.2R1-S2, 24.2R2;<br />
<br />
<br />
Junos OS Evolved:<br />
<br />
<br />
<br />
* all versions before 22.4R3-S7-EVO,<br />
* 23.2-EVO <br />
<br />
versions before 23.2R2-S3-EVO,<br />
* 23.4-EVO versions before 23.4R2-S4-EVO,<br />
* 24.2-EVO versions before 24.2R2-EVO.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
5.90
Severity 3.x
MEDIUM