Product Affected

This issue affects Junos OS Evolved
Medium

CVSS: v3.1: 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CVSS: v4.0: 6.3 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem

An Authentication Bypass by Spoofing vulnerability in Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass certain security boundaries and cause a denial-of-service (DoS) condition on an affected device. This issue applies to Flexible Tunnel Interfaces (FTI) with encapsulation-based tunnels.

The following platforms are affected for the following tunneling protocols:

ProductProtocol
PTXGRE/IPIP/4in6/6in4
ACXGRE
QFXGRE/IPIP/4in6

 

Important security issues resolved include:

CVECVSSSummary
CVE-2020-101365.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
CVE-2024-75956.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
CVE-2025-230186.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
CVE-2025-230196.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.

 

This issue affects Junos OS Evolved: 

 

  • All versions before 22.2R3-S6-EVO, 
  • from 22.4 before 22.4R3-S7-EVO, 
  • from 23.2 before 23.2R2-S4-EVO, 
  • from 23.4 before 23.4R2-S4-EVO, 
  • from 24.2 before 24.2R2-EVO.

Solution

The following software releases have been updated to resolve this specific issue:

Junos OS Evolved: 22.2R3-S6-EVO, 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.

This issue is being tracked as 1853953 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2025-07-09: Initial Publication

Related Information