CVE-2025-52982
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an MX Series device with an MS-MPC is configured with two or more service sets which are both processing SIP calls, a specific sequence of call events will lead to a crash and restart of the MS-MPC. This issue affects Junos OS: * all versions before 21.2R3-S9, * 21.4 versions from 21.4R1, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S6. As the MS-MPC is EoL after Junos OS 22.4, later versions are not affected. This issue does not affect MX-SPC3 or SRX Series devices.
Published:Jul 11, 2025
Last Modified:Jan 23, 2026
EPS:Jul 11, 2025
EPSS Score:0.00043
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Junos
Juniper
Junos
Vendor
Juniper
Product
Mx10004
Juniper
Mx10004
Vendor
Juniper
Product
Mx10008
Juniper
Mx10008
Vendor
Juniper
Product
Mx2008
Juniper
Mx2008
Vendor
Juniper
Product
Mx2010
Juniper
Mx2010
Vendor
Juniper
Product
Mx2020
Juniper
Mx2020
Vendor
Juniper
Product
Mx204
Juniper
Mx204
Vendor
Juniper
Product
Mx240
Juniper
Mx240
Vendor
Juniper
Product
Mx304
Juniper
Mx304
Vendor
Juniper
Product
Mx480
Juniper
Mx480
Vendor
Juniper
Product
Mx960
Juniper
Mx960
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
