cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 10 of 34
CVE-2021-31359P3HIGHCVSS 7.8≥ 15.1, < 15.1R7-S10≥ 17.4, < 17.4R3-S5+11 more2021-10-19
CVE-2021-31359 [HIGH] CWE-121 CVE-2021-31359: A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. Continued processing of malicious input will repeatedly crash the system and sustain t
nvd
CVE-2022-22161P3HIGHCVSS 7.5≥ unspecified, < 18.3R3-S6≥ 18.4, < 18.4R2-S9, 18.4R3-S9+10 more2022-01-19
CVE-2022-22161 [HIGH] CWE-400 CVE-2022-22161: An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port. Continued receipted of a flood will create a sustained Denial of Service (
nvd
CVE-2022-22221P3HIGHCVSS 7.8≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R1-S9, 19.2R3-S5+10 more2022-07-20
CVE-2022-22221 [HIGH] CVE-2022-22221: An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Netw An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Networks Junos OS on SRX Series and EX Series allows a locally authenticated attacker with low privileges to take full control over the device. One aspect of this vulnerability is that the attacker needs to be able to execute any of the "request ..." or "show syste
nvd
CVE-2022-22177P3HIGHCVSS 7.5≥ 12.3, < 12.3R12-S20≥ 15.1, < 15.1R7-S11+12 more2022-01-19
CVE-2022-22177 [HIGH] CWE-755 CVE-2022-22177: A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impacts any version of SNMP – v1,v2, v3 This issue affects: Juniper Networks Junos OS 12.3 version
nvd
CVE-2022-22171P3HIGHCVSS 7.5≥ 19.4, < 19.4R3-S7≥ 20.1, < 20.1R3-S3+6 more2022-01-19
CVE-2022-22171 [HIGH] CWE-754 CVE-2022-22171: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause the PFE to reset. This issue affects: Juniper Networks Junos OS 19.4 versions prior t
nvd
CVE-2022-22153P3HIGHCVSS 7.5≥ unspecified, < 18.2R3≥ 18.3, < 18.3R3+3 more2022-01-19
CVE-2022-22153 [HIGH] CWE-407 CVE-2022-22153: An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Th An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 allows an unauthenticated network attacker to cause latency in transit packet processing and even packet loss. If transit tra
nvd
CVE-2022-22180P3HIGHCVSS 7.5≥ 18.4, < 18.4R2-S10, 18.4R3-S10≥ 19.1, < 19.1R3-S7+10 more2022-01-19
CVE-2022-22180 [HIGH] CWE-754 CVE-2022-22180: An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability may cause traffic to stop being forwarded, or a crash of the fxpc process. An indication of th
nvd
CVE-2022-22170P3HIGHCVSS 7.5≥ 19.4, < 19.4R2-S6, 19.4R3-S6≥ 20.1, < 20.1R3-S2+5 more2022-01-19
CVE-2022-22170 [HIGH] CWE-772 CVE-2022-22170: A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause heap memory to leak and on exhaustion the PFE to reset. The heap memory utilization ca
nvd
CVE-2022-22198P3HIGHCVSS 7.5≥ 20.4, < 20.4R3≥ 21.1, < 21.1R2-S1, 21.1R3+1 more2022-04-14
CVE-2022-22198 [HIGH] CWE-824 CVE-2022-22198: An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. On all MX and SRX platforms, if the SIP ALG is enabled, an MS-MPC or MS-MIC, or
nvd
CVE-2022-22206P3HIGHCVSS 7.5≥ 20.2, < 20.2R3-S4≥ 20.3, < 20.3R3-S3+5 more2022-07-20
CVE-2022-22206 [HIGH] CWE-120 CVE-2022-22206: A Buffer Overflow vulnerability in the PFE of Juniper Networks Junos OS on SRX series allows an unau A Buffer Overflow vulnerability in the PFE of Juniper Networks Junos OS on SRX series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). The PFE will crash when specific traffic is scanned by Enhanced Web Filtering safe-search feature of UTM (Unified Threat management). Continued receipt of this specific traffic will
nvd
CVE-2022-22207P3HIGHCVSS 7.5≥ 20.1R1, < 20.1*≥ 20.2, < 20.2R3-S5+4 more2022-07-20
CVE-2022-22207 [HIGH] CWE-416 CVE-2022-22207: A Use After Free vulnerability in the Advanced Forwarding Toolkit (AFT) manager process (aftmand) of A Use After Free vulnerability in the Advanced Forwarding Toolkit (AFT) manager process (aftmand) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a kernel crash due to intensive polling of Abstracted Fabric (AF) interface statistics and thereby a Denial of Service (DoS). Continued gathering of AF interface statistics
nvd
CVE-2024-21614P3HIGHCVSS 7.5≥ 22.2, < 22.2R2-S2, 22.2R3≥ 22.3, < 22.3R2, 22.3R32024-01-12
CVE-2024-21614 [HIGH] CWE-754 CVE-2024-21614: An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (R An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause rpd to crash, leading to Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when NETCONF and gRPC are enabled, and a spe
nvd
CVE-2022-22175P3HIGHCVSS 7.5≥ 20.4, < 20.4R3-S1≥ 21.1, < 21.1R2-S2, 21.1R3+2 more2022-01-19
CVE-2022-22175 [HIGH] CWE-667 CVE-2022-22175: An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX S An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked attacker to cause a flowprocessing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. This issue can occur
nvd
CVE-2022-22184P3HIGHCVSS 7.5≥ 22.3, < 22.3R1-S12022-12-22
CVE-2022-22184 [HIGH] CWE-20 CVE-2022-22184: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, th
nvd
CVE-2023-22416P3HIGHCVSS 7.5≥ 20.4, < 20.4R3-S5≥ 21.1, < 21.1R3-S4+5 more2023-01-13
CVE-2023-22416 [HIGH] CWE-120 CVE-2023-22416: A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unau A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On all MX Series and SRX Series platform with SIP ALG enabled, when a malformed SIP packet is received, the flow processing daemon (flowd) will crash and restart. This issue affects: Juniper Netwo
nvd
CVE-2023-0026P3HIGHCVSS 7.5≥ unspecified, < 20.4R3-S8≥ 21.1, < 21.1*+8 more2023-06-21
CVE-2023-0026 [HIGH] CWE-20 CVE-2023-0026: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, t
nvd
CVE-2023-28982P3HIGHCVSS 7.5≥ 20.3, < 20.3R3-S2≥ 20.4, < 20.4R3-S6+3 more2023-04-17
CVE-2023-28982 [HIGH] CWE-401 CVE-2023-28982: A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scenario, when an attribute of an active BGP route is updated memory will leak. As rpd memory usa
nvd
CVE-2023-22413P3HIGHCVSS 7.5≥ unspecified, < 19.4R3-S9≥ 20.2, < 20.2R3-S5+8 more2023-01-13
CVE-2023-22413 [HIGH] CWE-703 CVE-2023-22413: An Improper Check or Handling of Exceptional Conditions vulnerability in the IPsec library of Junipe An Improper Check or Handling of Exceptional Conditions vulnerability in the IPsec library of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). On all MX platforms with MS-MPC or MS-MIC card, when specific IPv4 packets are processed by an IPsec6 tunnel, the Multiservices PIC Management Daemon
nvd
CVE-2023-28967P3HIGHCVSS 7.5≥ 21.1R1, < 21.1*≥ 21.2R1, < 21.2*+4 more2023-04-17
CVE-2023-28967 [HIGH] CWE-908 CVE-2023-28967: A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Junip A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial of Service (DoS) by crashing the Routing Protocol Daemon (rpd). This issue
nvd
CVE-2023-28965P3HIGHCVSS 7.5≥ unspecified, < 19.3R3-S7≥ 19.4, < 19.4R3-S11+6 more2023-04-17
CVE-2023-28965 [HIGH] CWE-703 CVE-2023-28965: An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. Storm control monitors the level of applicable
nvd