An Improper Resource Shutdown or Release vulnerability in...
High severity
Unreviewed
Published
Jul 11, 2025
to the GitHub Advisory Database
•
Updated Jul 11, 2025
Description
Published by the National Vulnerability Database
Jul 11, 2025
Published to the GitHub Advisory Database
Jul 11, 2025
Last updated
Jul 11, 2025
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When an MX Series device with an MS-MPC is configured with two or more service sets which are both processing SIP calls, a specific sequence of call events will lead to a crash and restart of the MS-MPC.
This issue affects Junos OS:
As the MS-MPC is EoL after Junos OS 22.4, later versions are not affected.
This issue does not affect MX-SPC3 or SRX Series devices.
References