CVE-2025-52952
Severity CVSS v4.0:
HIGH
Type:
CWE-787
Out-of-bounds Write
Publication date:
11/07/2025
Last modified:
26/01/2026
Description
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS).<br />
<br />
Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.<br />
<br />
This issue affects Juniper Networks:<br />
Junos OS:<br />
* All versions before 22.2R3-S1,<br />
* from 22.4 before 22.4R2.<br />
<br />
<br />
This feature is not enabled by default.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 22.2 (excluding) | |
| cpe:2.3:o:juniper:junos:22.2:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r1-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r2-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r2-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.2:r3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:2x100ge_\+_4x10ge_mpc5e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:2x100ge_\+_4x10ge_mpc5eq:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



