CVE-2025-30646
A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. When an LLDP telemetry subscription is active, receipt of a specifically malformed LLDP TLV causes the l2cpd process to crash and restart. This issue affects: Junos OS: * All versions before 21.2R3-S9, * from 21.4 before 21.4R3-S10, * from 22.2 before 22.2R3-S6, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S4, * from 24.2 before 24.2R2; Junos OS Evolved: * All versions before 21.4R3-S10-EVO, * from 22.2-EVO before 22.2R3-S6-EVO, * from 22.4-EVO before 22.4R3-S6-EVO, * from 23.2-EVO before 23.2R2-S3-EVO, * from 23.4-EVO before 23.4R2-S4-EVO, * from 24.2-EVO before 24.2R2-EVO.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/V:C/RE:M
- EPSS probability
- 0.24%
- CWE
- CWE-195
- Published
- 2025-04-09
- Last modified
- 2026-03-12
Affected products
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS Evolved
Weakness type
Related vulnerabilities
- CVE-2026-85441 — MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length
- CVE-2026-18444 — Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
- CVE-2026-62959 — Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
- CVE-2026-55737 — Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
- CVE-2026-55991 — Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
- CVE-2026-49840 — FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
- CVE-2026-41682 — pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion
- CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp