cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 1 of 34
CVE-2023-36845P1CRITICALCVSS 9.8KEVPoCfixed in 20.4R3-S9≥ 21.1, < 21.1*+8 more2023-08-17
CVE-2023-36845 [CRITICAL] CWE-473 CVE-2023-36845: A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Serie A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of
nvd
CVE-2023-36844P1MEDIUMCVSS 5.3KEVPoCRansomwarefixed in 20.4R3-S9≥ 21.1, < 21.1*+8 more2023-08-17
CVE-2023-36844 [MEDIUM] CWE-473 CVE-2023-36844: A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Serie A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow ch
nvd
CVE-2023-36847P1MEDIUMCVSS 5.3KEVPoCRansomwarefixed in 20.4R3-S8≥ 21.1, < 21.1*+7 more2023-08-17
CVE-2023-36847 [MEDIUM] CWE-306 CVE-2023-36847: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Seri A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web,
nvd
CVE-2023-36846P1MEDIUMCVSS 5.3KEVPoCfixed in 20.4R3-S8≥ 21.1, < 21.1*+7 more2023-08-17
CVE-2023-36846 [MEDIUM] CWE-306 CVE-2023-36846: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Ser A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a
nvd
CVE-2020-1631P1CRITICALCVSS 9.8KEV≥ 12.3, < 12.3R12-S16≥ 12.3X48, < 12.3X48-D101, 12.3X48-D105+16 more2020-05-04
CVE-2020-1631 [CRITICAL] CWE-22 CVE-2020-1631: A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Fir A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal. Using this vulnerability, an attacker may be able to inject commands into
nvd
CVE-2023-36851P1MEDIUMCVSS 5.3KEV≥ 21.2, < 21.2R3-S8≥ 21.4, < 21.4R3-S6+5 more2023-09-27
CVE-2023-36851 [MEDIUM] CWE-306 CVE-2023-36851: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Ser A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary
nvd
CVE-2025-21590P1MEDIUMCVSS 4.4KEVfixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-03-12
CVE-2025-21590 [MEDIUM] CWE-653 CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue is not exploitable from the Junos
nvd
CVE-2022-22242P1MEDIUMCVSS 6.1ExploitedPoC≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S6+11 more2022-10-18
CVE-2022-22242 [MEDIUM] CWE-79 CVE-2022-22242: A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allow A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.
nvd
CVE-2024-21620P1MEDIUMCVSS 6.1Exploitedfixed in 20.4R3-S10≥ 21.2, < 21.2R3-S8+7 more2024-01-25
CVE-2024-21620 [MEDIUM] CWE-79 CVE-2024-21620: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. A specific
nvd
CVE-2024-21591P2CRITICALCVSS 9.8fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S7+6 more2024-01-12
CVE-2024-21591 [CRITICAL] CWE-787 CVE-2024-21591: An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Ser An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. This issue is caused by use of an insecure function allowing an attacker to overwrite a
nvd
CVE-2003-0001P3MEDIUMCVSS 5.0PoC≥ unspecified, < 18.4R3-S11≥ 19.1, < 19.1R2-S3, 19.1R3-S7+15 more2003-01-17
CVE-2003-0001 [MEDIUM] CWE-200 CVE-2003-0001: Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, whi Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
nvd
CVE-2021-0254P2CRITICALCVSS 9.8≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S11+12 more2021-04-22
CVE-2021-0254 [CRITICAL] CWE-131 CVE-2021-0254: A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allo A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution (RCE). Continued receipt and processing of these packets will sustain the
nvd
CVE-2018-0001P2CRITICALCVSS 9.8≥ 12.1X46, < 12.1X46-D67≥ 12.3, < 12.3R12-S5+7 more2018-01-10
CVE-2018-0001 [CRITICAL] CWE-416 CVE-2018-0001: A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the context of the J-Web process. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D67; 12.3 versions prior to 12.3R12-S5;
nvd
CVE-2016-1265P2CRITICALCVSS 9.8vall versions prior to 15.1R22017-10-13
CVE-2016-1265 [CRITICAL] CWE-200 CVE-2016-1265: A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary cod A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to
nvd
CVE-2021-31384P2CRITICALCVSS 10.0≥ 20.4R1, < 20.4*≥ 21.1, < 21.1R1-S1, 21.1R22021-10-19
CVE-2021-31384 [CRITICAL] CWE-285 CVE-2021-31384: Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management con
nvd
CVE-2019-0008P2CRITICALCVSS 9.8v14.1X53≥ 15.1X53, < 15.1X53-D235+8 more2019-04-10
CVE-2019-0008 [CRITICAL] CWE-121 CVE-2019-0008: A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. Affected releases are Juniper Networks Junos OS
nvd
CVE-2017-2343P2CRITICALCVSS 9.8v12.3X48 from 12.3X48-D30 and prior to 12.3X48-D35v15.1X49 from 15.1X49-D40 and prior to 15.1X49-D502017-07-17
CVE-2017-2343 [CRITICAL] CWE-798 CVE-2017-2343: The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide simple integration of user profiles on top of the existing firewall polices. As part of an internal security review of the UserFW services authentication API, hardcoded credentials were identified and removed which
nvd
CVE-2021-0249P2CRITICALCVSS 9.8≥ 15.1X49, < 15.1X49-D190≥ 17.4, < 17.4R2-S9+6 more2021-04-22
CVE-2021-0249 [CRITICAL] CWE-120 CVE-2021-0249: On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet For On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS may allow an attacker to arbitrarily execute code or commands on the target to take over or otherwise impact the device by sending crafted packets to or through the device. This issue affects: Juniper
nvd
CVE-2023-28962P2CRITICALCVSS 9.8≥ unspecified, < 19.4R3-S11≥ 20.1R1, < 20.1*+10 more2023-04-17
CVE-2023-28962 [CRITICAL] CWE-287 CVE-2023-28962: An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.4R3-S11; 20.1 version 20.1R1 and later versions;
nvd
CVE-2022-22241P2CRITICALCVSS 9.8≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S6+11 more2022-10-18
CVE-2022-22241 [CRITICAL] CWE-20 CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may a An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affe
nvd
1 / 34Next →
Juniper Networks Junos Os vulnerabilities | cvebase