cbcvebase.

Juniper Junos vulnerabilities

782 known vulnerabilities affecting juniper/junos.

Total CVEs
782
CISA KEV
7
actively exploited
Public exploits
13
Exploited in wild
10
Severity breakdown
CRITICAL42HIGH352MEDIUM386LOW2

Vulnerabilities

Page 21 of 40
CVE-2014-3815P3HIGHCVSS 7.8v12.1x46v12.1x472014-07-11
CVE-2014-3815 [HIGH] CWE-20 CVE-2014-3815: Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
nvd
CVE-2026-57022P3MEDIUMCVSS 5.9fixed in 23.2v23.2+20 more2026-07-09
CVE-2026-57022 [MEDIUM] CWE-754 CVE-2026-57022: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device initiates a TCP connection to an attacker-controlled system that respond
nvd
CVE-2026-57054P3MEDIUMCVSS 5.8fixed in 23.2v23.2+47 more2026-07-09
CVE-2026-57054 [MEDIUM] CWE-706 CVE-2026-57054: A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable. If an MX Series device is configured with web filtering, and an attacker sends a re
nvd
CVE-2017-2348P3HIGHCVSS 7.5v14.1x53v15.1+2 more2017-07-17
CVE-2017-2348 [HIGH] CWE-400 CVE-2017-2348: The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon re The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon receipt of an invalid IPv6 UDP packet. Both high CPU utilization and repeated crashes of the jdhcpd daemon can result in a denial of service as DHCP service is interrupted. No other Juniper Networks products or platforms are affected by this issue. Affected
nvd
CVE-2021-0222P3HIGHCVSS 7.4v14.1x53v15.1+12 more2021-01-15
CVE-2021-0222 [HIGH] CWE-16 CVE-2021-0222: A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) t A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets, which should be discarded, are instead replicated and sent to the RE. Over time, a Denial of Service (DoS) occurs.
nvd
CVE-2021-0259P3HIGHCVSS 7.4v17.3v17.4+11 more2021-04-22
CVE-2021-0259 [HIGH] CWE-755 CVE-2021-0259: Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the overlay network sends a high volume
nvd
CVE-2021-0210P3MEDIUMCVSS 6.8v12.3v17.3+11 more2021-01-15
CVE-2021-0210 [MEDIUM] CWE-200 CVE-2021-0210: An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticate An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevate their privileges over the target system through opportunistic use of an authenticated users session. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S17; 17.3 versions prior to 17.3R3-S10; 17.4 versions
nvd
CVE-2020-1600P3MEDIUMCVSS 6.5v12.3x48v15.1+14 more2020-01-15
CVE-2020-1600 [MEDIUM] CWE-400 CVE-2020-1600: In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consump In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite loop causing a high CPU usage Denial of Service (DoS) condition. This issue affects both SNMP over IPv4 and IPv6.
nvd
CVE-2020-1637P3MEDIUMCVSS 6.5v12.3x48v15.1x49+10 more2020-04-08
CVE-2020-1637 [MEDIUM] CWE-288 CVE-2020-1637: A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may a A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Controller (IC) is configured as an IP address range instead of an IP address/netmask. See the Wo
nvd
CVE-2016-1280P3MEDIUMCVSS 6.5≤ 12.1x44v12.1x46+12 more2016-09-09
CVE-2016-1280 [MEDIUM] CWE-297 CVE-2016-1280: PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1R4, 15.1X49 before 15.1X49-D20, 15.1X53 before 15.1X53-D60, and 16.1 before 16.1R1 allow remote at
nvd
CVE-2018-0018P3MEDIUMCVSS 5.9v12.1x46v12.3x48+1 more2018-04-11
CVE-2018-0018 [MEDIUM] CWE-200 CVE-2018-0018: On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted pack On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading to information disclosure which an attacker may use to gain control of the target device or other internal devices, systems or services protected by the SRX Series device. This issue only applies to devi
nvd
CVE-2014-6451P4HIGHCVSS 7.8≤ 15.1x492015-10-16
CVE-2014-6451 [HIGH] CVE-2014-6451: J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service (system reboot) via unspecified vectors.
nvd
CVE-2024-30401P3MEDIUMCVSS 5.9v21.2v21.4+2 more2024-04-12
CVE-2024-30401 [MEDIUM] CWE-125 CVE-2024-30401: An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C, may allow an attacker to exploit a stack-based buffer overflow, leading to a reboot of the FPC. Through code review, it was determined that the interfac
nvd
CVE-2009-3487P4LOWCVSS 3.5PoCv8.52009-09-30
CVE-2009-3487 [LOW] CWE-79 CVE-2009-3487: Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision param
nvd
CVE-2018-15505P4HIGHCVSS 7.5v12.3v12.3x48+10 more2018-08-18
CVE-2018-15505 [HIGH] CWE-476 CVE-2018-15505: An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST requ An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
nvd
CVE-2025-60011P3MEDIUMCVSS 5.8fixed in 22.4v22.4+4 more2026-01-15
CVE-2025-60011 [MEDIUM] CWE-754 CVE-2025-60011: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an affected device receives a specific optional, transitive BGP attribute over an
nvd
CVE-2026-33773P3MEDIUMCVSS 5.8v23.4v24.22026-04-09
CVE-2026-33773 [MEDIUM] CWE-1419 CVE-2026-33773: An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Junip An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or inet6 filter is applied on an IRB interface and on a
nvd
CVE-2015-5358P4HIGHCVSS 7.1v12.1x44v12.1x46+11 more2015-07-14
CVE-2015-5358 [HIGH] CWE-399 CVE-2015-5358: Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D16, 14.1X55 b
nvd
CVE-2016-1274P4HIGHCVSS 7.5v14.1x532016-04-15
CVE-2016-1274 [HIGH] CWE-19 CVE-2016-1274: Juniper Junos OS 14.1X53 before 14.1X53-D30 on QFX Series switches allows remote attackers to cause Juniper Junos OS 14.1X53 before 14.1X53-D30 on QFX Series switches allows remote attackers to cause a denial of service (PFE panic) via a high rate of unspecified VXLAN packets.
nvd
CVE-2026-57021P3MEDIUMCVSS 5.3v23.2v23.2-r1+43 more2026-07-09
CVE-2026-57021 [MEDIUM] CWE-787 CVE-2026-57021: An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS o An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted re
nvd
Juniper Junos vulnerabilities | cvebase