CVE-2025-60007 is a NULL Pointer Dereference vulnerability in the chassisd daemon of Juniper Networks Junos OS on MX, SRX, and EX Series devices. A low-privileged local attacker can trigger a Denial-of-Service (DoS) by executing a specially crafted 'show chassis' command, causing chassisd to crash and reinitialize all components except the Routing Engine, leading to a temporary service outage. This vulnerability has a CVSS score of 5.5 (Medium) due to its local attack vector and high impact on availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 22.4R3-S8CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.2, < 23.2R2-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.4, < 23.4R2-S6CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.2, < 24.2R2-S2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.4, < 24.4R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
2026-01 Security Bulletin: Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash (CVE-2025-60007)
Mar 16, 20262026-01 Security Bulletin: Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash (CVE-2025-60007)
Mar 11, 20262026-01 Security Bulletin: Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash (CVE-2025-60007)
Jan 26, 2026