Medium severity6.5NVD Advisory· Published Jul 11, 2025· Updated Jun 17, 2026
CVE-2025-52952
CVE-2025-52952
Description
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS).
Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
This issue affects Juniper Networks: Junos OS: * All versions before 22.2R3-S1, * from 22.4 before 22.4R2.
This feature is not enabled by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*range: <22.2
- cpe:2.3:o:juniper:junos:22.2:-:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r1-s1:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r1-s2:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r1:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r2-s1:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r2-s2:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r2:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.2:r3:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*
- (no CPE)range: <22.2R3-S1, 22.4<22.4R2
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.