Junos OS: MX Series, SRX Series: Processing of specific SIP INVITE messages by the SIP ALG will lead to an FPC crash
Published Apr 9, 2025
8.7
HIGHCVSS 4.0
EPSS 0.42%
Description
An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If the SIP ALG processes specifically formatted SIP invites, a memory corruption will occur which will lead to a crash of the FPC processing these packets. Although the system will automatically recover with the restart of the FPC, subsequent SIP invites will cause the crash again and lead to a sustained DoS.
This issue affects Junos OS on MX Series and SRX Series:
* all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S3, * 24.2 versions before 24.2R1-S2, 24.2R2.
Affected products
-
- Version 0StatusaffectedConstraints<21.2R3-S9
- Version 21.4StatusaffectedConstraints<21.4R3-S10
- Version 22.2StatusaffectedConstraints<22.2R3-S6
- Version 22.4StatusaffectedConstraints<22.4R3-S5
- Version 23.2StatusaffectedConstraints<23.2R2-S3
- Version 23.4StatusaffectedConstraints<23.4R2-S3
- Version 24.2StatusaffectedConstraints<24.2R1-S2, 24.2R2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | unaffected |
|
- < 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.2
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 22.4
- 23.2
- 23.2
- 23.2
- 23.2
- 23.2
- 23.2
- 23.2
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 24.2
- 24.2
- 24.2
- 24.2
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: 21.2R3-S9,
21.4R3-S10, 22.2R3-S6, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10507 Advisory
- https://supportportal.juniper.net/JSA96466 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10507 | Advisory | |
| https://supportportal.juniper.net/JSA96466 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.