HomeJuniperCVE-2025-60010

CVE-2025-60010

MEDIUM
5.3CVSS
Published: 2025-10-09
Updated: 2026-01-23
AI Analysis

Description

A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users for whom the RADIUS server has responded with a reject and required the user to change the password as their password was expired. Therefore the policy mandating the password change is not enforced. This does not allow users to login with a wrong password, but only with the correct but expired one. This issue affects: Junos OS:  * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S3, 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S8-EVO, * 23.2 versions before 23.2R2-S4-EVO, * 23.4 versions before 23.4R2-S5-EVO, * 24.2 versions before 24.2R2-S1-EVO, * 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.

CVSS Metrics

Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:X
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-262

Metadata

Primary Vendor
JUNIPER
Published
10/9/2025
Last Modified
1/23/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

juniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junosjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolvedjuniper : junos_os_evolved

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-60010 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com