{"id":"CVE-2025-52960","title":"A Buffer Copy without Checking Size of Input vulnerability in the \n\nSession Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of…","summary":"A Buffer Copy without Checking Size of Input vulnerability in the \n\nSession Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-120"],"vendor":"juniper","product":"junos","affected":["junos < 22.4","junos = 22.4","junos = 23.2","junos = 23.4","junos = 24.2"],"patched":["junos 22.4"],"published":"2025-10-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-52960","references":[{"url":"https://kb.juniper.net/JSA103143","label":"sirt@juniper.net"},{"url":"https://supportportal.juniper.net/JSA103143","label":"sirt@juniper.net"}],"tags":["nvd"],"epss":0.00331,"epssPercentile":0.24276,"ingestedAt":"2026-10-08T13:42:55.040Z","slug":"CVE-2025-52960","body":"## Overview\n\nA Buffer Copy without Checking Size of Input vulnerability in the \n\nSession Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\n\nWhen memory utilization is high, and specific SIP packets are received, flowd/mspmand crashes. While the system recovers automatically, the disruption can significantly impact service stability. Continuous receipt of these specific SIP packets, while high utilization is present, will cause a sustained DoS condition. The utilization is outside the attackers control, so they would not be able to deterministically exploit this.\nThis issue affects Junos OS on SRX Series and MX Series: \n\n\n  *  All versions before 22.4R3-S7,\n  *  from 23.2 before 23.2R2-S4, \n  *  from 23.4 before 23.4R2-S5, \n  *  from 24.2 before 24.2R2.\n\n## Affected\n\n- `junos < 22.4`\n- `junos = 22.4`\n- `junos = 23.2`\n- `junos = 23.4`\n- `junos = 24.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `junos 22.4`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}