Juniper Screenos vulnerabilities
16 known vulnerabilities affecting juniper/screenos.
Total CVEs
16
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2018-0014MEDIUMCVSS 6.5v6.3.0r1v6.3.0r2+23 more2018-01-10
CVE-2018-0014 [MEDIUM] CVE-2018-0014: Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
nvd
CVE-2017-2336MEDIUMCVSS 5.4v6.3.02017-07-17
CVE-2017-2336 [CRITICAL] CWE-79 CVE-2017-2336: A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScr
A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the attacker to effectively execute commands with the permissions o
nvd
CVE-2017-2337MEDIUMCVSS 5.4v6.3.02017-07-17
CVE-2017-2337 [HIGH] CWE-79 CVE-2017-2337: A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetSc
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with
nvd
CVE-2017-2338MEDIUMCVSS 5.4v6.3.02017-07-17
CVE-2017-2338 [HIGH] CWE-79 CVE-2017-2338: A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetSc
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with
nvd
CVE-2017-2335MEDIUMCVSS 5.4v6.3.02017-07-17
CVE-2017-2335 [HIGH] CWE-79 CVE-2017-2335: A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetSc
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with
nvd
CVE-2017-2339MEDIUMCVSS 5.4v6.3.02017-07-17
CVE-2017-2339 [HIGH] CWE-79 CVE-2017-2339: A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetSc
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with
nvd
CVE-2016-1268HIGHCVSS 7.5v6.3.02016-04-15
CVE-2016-1268 [HIGH] CWE-20 CVE-2016-1268: The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attacker
The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.
nvd
CVE-2015-7754HIGHCVSS 8.1≤ 6.3.02016-01-08
CVE-2015-7754 [HIGH] CWE-20 CVE-2015-7754: Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.
nvd
CVE-2015-7755CRITICALCVSS 9.8KEVv6.3.02015-12-19
CVE-2015-7755 [CRITICAL] CWE-287 CVE-2015-7755: Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by ent
nvd
CVE-2015-7756MEDIUMCVSS 5.0v6.2.0r15v6.2.0r16+3 more2015-12-19
CVE-2015-7756 [MEDIUM] CWE-310 CVE-2015-7756: The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r1
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote atta
nvd
CVE-2015-7750MEDIUMCVSS 5.0≤ 6.3.0v6.3.02015-10-19
CVE-2015-7750 [MEDIUM] CWE-20 CVE-2015-7750: The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with Sc
The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.
nvd
CVE-2014-3813HIGHCVSS 7.8≤ 6.3.0v6.0.0+2 more2014-06-13
CVE-2014-3813 [HIGH] CVE-2014-3813: Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6
Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via vectors related to a DNS lookup.
nvd
CVE-2014-3814HIGHCVSS 7.8≤ 6.3.0v6.0.0+2 more2014-06-13
CVE-2014-3814 [HIGH] CWE-20 CVE-2014-3814: The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use
The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via a sequence of malformed packets to the device IP.
nvd
CVE-2014-2842HIGHCVSS 7.8≤ 6.3.0v5.4.0+3 more2014-04-15
CVE-2014-2842 [HIGH] CWE-399 CVE-2014-2842: Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and res
Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.
nvd
CVE-2013-7313MEDIUMCVSS 5.4≤ 6.3.0v5.4.0+3 more2014-01-23
CVE-2013-7313 [MEDIUM] CVE-2013-7313: The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not c
The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet info
nvd
CVE-2013-6958HIGHCVSS 7.1v5.4.0v6.2.0+1 more2013-12-13
CVE-2013-6958 [HIGH] CVE-2013-6958: Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disab
Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet.
nvd