Juniper Networks Junos OS and Junos OS Evolved Buffer Access Vulnerability in RPD Leading to Denial-of-Service

Vulnerability

A buffer access vulnerability with an incorrect length value has been identified in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to cause a denial-of-service condition. The issue arises when a specific ICMPv6 packet is sent to an interface configured to send router advertisements. This causes the RPD process to crash and restart. Continued receipt of the packet leads to a sustained denial-of-service condition. The vulnerability only affects systems with IPv6 enabled.

Impact

Exploitation of this vulnerability causes the RPD process to crash and restart, leading to a denial-of-service condition that can be sustained with continued receipt of the malicious ICMPv6 packets.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.