CVE-2025-21590 is an improper isolation vulnerability in Juniper Networks Junos OS kernel, affecting numerous versions across multiple release trains. A local attacker with high privileges and shell access can inject arbitrary code, compromising device integrity. This vulnerability has a CVSS score of 4.4 (Medium) due to its local attack vector and high privileges required, but it can lead to high integrity impact. Notably, this CVE is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community discussion and media coverage despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:-:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.