CVE-2025-21590

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 14, 2025
CWE ID 653

Summary

CVE-2025-21590 is a kernel vulnerability in Juniper Networks Junos OS that puts affected devices at risk of compromise. An attacker with high privileges and shell access can inject arbitrary code, exploiting the system's improper isolation or compartmentalization. The vulnerability does not affect Junos CLI access, but it poses a threat to devices running Junos OS: - All versions before 21.2R3-S9 - 21.4 versions before 21.4R3-S10 - 22.2 versions before 22.2R3-S6 - 22.4 versions before 22.4R3-S6 - 23.2 versions before 23.2R2-S3 - 23.4 versions before 23.4R2-S4 - 24.2 versions before 24.2R1-S2 and 24.2R2 Local attackers leveraging this vulnerability can compromise the integrity of the affected device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks