📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 16m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h Global vulnerability Artificial Intelligence and Technology HIGH 16m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h Global vulnerability Artificial Intelligence and Technology HIGH 16m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h
Vulnerabilities

CVE-2025-60003

High
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (
CWE-126 — Weakness Type
Published: Jan 15, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer.
This issue can only happen if one or both of the BGP peers of the receiving session are non-4-byte-AS capable as determined from the advertised capabilities during BGP session establishment. Junos OS and Junos OS Evolved default behavior is 4-byte-AS capable unless this has been specifically disabled by configuring:

[ protocols bgp ... disable-4byte-as ]


Established BGP sessions can be checked by executing:

show bgp neighbor <IP address> | match "4 byte AS"


This issue affects:

Junos OS: 

* all versions before 22.4R3-S8,
* 23.2 versions before 23.2R2-S5,
* 23.4 versions before 23.4R2-S6,
* 24.2 versions before 24.2R2-S2,
* 24.4 versions before 24.4R2;


Junos OS Evolved: 

* all versions before 22.4R3-S8-EVO,
* 23.2 versions before 23.2R2-S5-EVO,
* 23.4 versions before 23.4R2-S6-EVO,
* 24.2 versions before 24.2R2-S2-EVO,
* 24.4 versions before 24.4R2-EVO.

🤖 AI Executive Summary

A buffer over-read vulnerability in Juniper Junos OS routing protocol daemon (rpd) allows unauthenticated network attackers to cause denial-of-service by sending specially crafted BGP updates with optional transitive attributes. The vulnerability affects multiple Junos versions and can crash the routing daemon, disrupting network connectivity. This is particularly critical for organizations running non-4-byte-AS capable BGP sessions, which are less common but still present in legacy deployments across Saudi infrastructure.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 11:01
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi telecommunications infrastructure (STC, Mobily, Zain), banking sector (SAMA-regulated institutions), and government networks that rely on Juniper routing equipment for core BGP peering. Energy sector (ARAMCO, SEC) and critical infrastructure operators using Junos devices are at elevated risk. The DoS impact could disrupt international connectivity and inter-AS routing, affecting business continuity. Organizations with legacy BGP configurations (disabled 4-byte-AS) face higher exploitation probability.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Banking and Financial Services (SAMA-regulated) Government and Defense Energy (ARAMCO, SEC) Critical Infrastructure Large Enterprise Networks
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Verify BGP peer configurations: Execute 'show bgp neighbor <IP> | match "4 byte AS"' on all Junos devices to identify non-4-byte-AS capable sessions
2. Implement BGP input filtering to reject malformed optional transitive attributes at peering points
3. Enable BGP session monitoring and alerting for rpd crashes

PATCHING GUIDANCE:
- Junos OS: Upgrade to 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, or 24.4R2 (or later)
- Junos OS Evolved: Upgrade to corresponding -EVO versions
- Prioritize devices with non-4-byte-AS BGP sessions
- Schedule maintenance windows to minimize routing disruption

COMPENSATING CONTROLS (if immediate patching unavailable):
- Restrict BGP peering to trusted ASNs only
- Implement strict BGP attribute validation at ingress
- Deploy BGP route filtering policies to drop suspicious optional transitive attributes
- Enable rpd restart monitoring with automatic failover to backup routing devices
- Consider disabling optional transitive attribute processing if operationally feasible

DETECTION:
- Monitor syslog for rpd crashes and restarts: 'rpd[*]: PANIC'
- Alert on BGP session flaps from specific peers
- Baseline normal BGP update patterns and flag anomalies
- Implement NetFlow/sFlow monitoring for traffic loss during incidents
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. التحقق من تكوينات نظير BGP: تنفيذ 'show bgp neighbor <IP> | match "4 byte AS"' على جميع أجهزة Junos لتحديد الجلسات غير القادرة على 4 بايت AS
2. تطبيق تصفية مدخلات BGP لرفض السمات الاختيارية المشكوك فيها
3. تفعيل مراقبة التنبيهات لأعطال rpd

إرشادات التصحيح:
- Junos OS: الترقية إلى 22.4R3-S8 أو 23.2R2-S5 أو 23.4R2-S6 أو 24.2R2-S2 أو 24.4R2 أو أحدث
- Junos OS Evolved: الترقية إلى الإصدارات -EVO المقابلة
- إعطاء الأولوية للأجهزة ذات جلسات BGP غير القادرة على 4 بايت AS
- جدولة نوافذ الصيانة لتقليل تعطل التوجيه

الضوابط البديلة:
- تقييد نظير BGP بـ ASNs موثوقة فقط
- تطبيق التحقق الصارم من سمات BGP عند الدخول
- نشر سياسات تصفية مسارات BGP لحذف السمات المريبة
- تفعيل مراقبة إعادة تشغيل rpd مع الفشل التلقائي
- النظر في تعطيل معالجة السمات الاختيارية إن أمكن

الكشف:
- مراقبة السجلات لأعطال rpd: 'rpd[*]: PANIC'
- التنبيه على تقلبات جلسات BGP
- مراقبة أنماط تحديثات BGP الطبيعية
- تطبيق مراقبة NetFlow/sFlow
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.6.2 - Restrictions on software installation ECC 2024 A.8.2.3 - Segregation of networks ECC 2024 A.13.1.3 - Segregation on networks
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - System and information integrity DE.CM-8 - Vulnerability scans RS.MI-2 - Incidents are mitigated
🟡 ISO 27001:2022
A.12.6.1 - Management of technical vulnerabilities A.12.6.2 - Restrictions on software installation A.14.2.1 - Secure development policy A.8.2.3 - Segregation of networks
🟣 PCI DSS v4.0.1
6.2 - Security patches and updates 11.2 - Vulnerability scanning
📦 Affected Products / CPE 50 entries
juniper:junos
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:22.4
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.2
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:23.4
juniper:junos:24.2
juniper:junos:24.2
juniper:junos:24.2
juniper:junos:24.2
juniper:junos:24.2
juniper:junos:24.2
juniper:junos:24.4
juniper:junos:24.4
juniper:junos:24.4
juniper:junos:24.4
juniper:junos_os_evolved
juniper:junos_os_evolved:22.4
juniper:junos_os_evolved:22.4
juniper:junos_os_evolved:22.4
juniper:junos_os_evolved:22.4
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-126
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-01-15
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-126
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.