Juniper Junos OS Evolved vulnerabilities
247 known vulnerabilities affecting juniper/junos_os_evolved.
Total CVEs
247
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH95MEDIUM150
Vulnerabilities
Page 13 of 13
CVE-2026-33799P4MEDIUMCVSS 4.3fixed in 21.2v21.2+58 more2026-07-09
CVE-2026-33799 [MEDIUM] CWE-787 CVE-2026-33799: An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Jun
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash an
nvd
CVE-2020-1620P4MEDIUMCVSS 5.5fixed in 19.3r12020-04-08
CVE-2020-1620 [MEDIUM] CWE-664 CVE-2020-1620: A local, authenticated user with shell can obtain the hashed values of login passwords via configd s
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
nvd
CVE-2020-1622P4MEDIUMCVSS 5.5fixed in 19.1r12020-04-08
CVE-2020-1622 [MEDIUM] CWE-664 CVE-2020-1622: A local, authenticated user with shell can obtain the hashed values of login passwords and shared se
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
nvd
CVE-2020-1621P4MEDIUMCVSS 5.5fixed in 19.3r12020-04-08
CVE-2020-1621 [MEDIUM] CWE-664 CVE-2020-1621: A local, authenticated user with shell can obtain the hashed values of login passwords via configd t
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
nvd
CVE-2024-21615P4MEDIUMCVSS 5.0fixed in 21.2v21.2+7 more2024-04-12
CVE-2024-21615 [MEDIUM] CWE-276 CVE-2024-21615: An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved all
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system.
On all Junos OS and Junos OS Evolved platforms, when NETCONF traceoptions are configured, and a super-user performs specific actions via NETCONF, then a low-privil
nvd
CVE-2023-36836P4MEDIUMCVSS 4.7fixed in 20.4v20.4+6 more2023-07-14
CVE-2023-36836 [MEDIUM] CWE-908 CVE-2023-36836: A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Net
A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, in a Multicast only Fast Reroute (MoFRR) scenario, the rpd process can
nvd
CVE-2021-0298P4MEDIUMCVSS 4.7v18.3v19.1+4 more2021-10-19
CVE-2021-0298 [MEDIUM] CWE-362 CVE-2021-0298: A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an
A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS) condition. Continued execution of th
nvd
← Previous13 / 13