GPU VulnDB

Database/Firmware, BMC & network fabric

Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE): FABRIC DOS: a crafted BGP UPDATE crashes the routing protocol

CVE-2025-21602Firmware, BMC & network fabriccurated

Impact

FABRIC DOS: a crafted BGP UPDATE crashes the routing protocol daemon. In a BGP-underlay leaf/spine the rpd going down is the rack losing reachability; because BGP UPDATEs propagate, a single malicious or malformed announcement can ripple to every device that accepts it, which is how a one-switch bug becomes a fabric-wide outage.

Who can reach it

Unauthenticated attacker able to get a crafted UPDATE into the BGP mesh — either as a peer, or upstream of one, since the message is forwarded along.

What to do

Junos/Junos Evolved upgrade plus reboot, staged so ECMP paths are never both down. Interim: BGP UPDATE filtering and strict inbound policy at the fabric edge, plus bgp-error-tolerance style handling where the release supports it — live config changes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.