Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 15 of 34
CVE-2021-0204P3HIGHCVSS 7.8≥ 15.1, < 15.1R7-S8≥ 15.1X49, < 15.1X49-D230+13 more2021-01-15
CVE-2021-0204 [HIGH] CWE-250 CVE-2021-0204: A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Jun
A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos OS may allow a locally authenticated shell user the ability to create and read database files generated by the dexp utility, including password hashes of local users. Since dexp is shipped with setuid permissions enabled and is owned b
nvd
CVE-2020-1672P3HIGHCVSS 7.5≥ 17.3, < 17.3R3-S9≥ 17.4, < 17.4R2-S11, 17.4R3-S2, 17.4R3-S3+10 more2020-10-16
CVE-2020-1672 [HIGH] CWE-20 CVE-2020-1672: On Juniper Networks Junos OS devices configured with DHCPv6 relay enabled, receipt of a specific DHC
On Juniper Networks Junos OS devices configured with DHCPv6 relay enabled, receipt of a specific DHCPv6 packet might crash the jdhcpd daemon. The jdhcpd daemon automatically restarts without intervention, but continuous receipt of specific crafted DHCP messages will repeatedly crash jdhcpd, leading to an extended Denial of Service (DoS) condition. Only D
nvd
CVE-2021-0202P3HIGHCVSS 7.5v17.3R3-S8v17.4R3-S2+6 more2021-01-15
CVE-2021-0202 [HIGH] CWE-400 CVE-2021-0202: On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentr
On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Customer Edge (CE) device may cause memory leak in the MPC which can cause an out of memory and MPC
nvd
CVE-2021-0250P3HIGHCVSS 7.5≥ 17.4R1, < unspecified≥ 17.4, < 17.4R2-S6, 17.4R3+6 more2021-04-22
CVE-2021-0250 [HIGH] CVE-2021-0250: In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) f
In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) feature is enable, a vulnerability in the Routing Protocol Daemon (RPD) process of Juniper Networks Junos OS allows an attacker to send a specific crafted BGP update message causing the RPD service to core, creating a Denial of Service (DoS) Condition. Continued r
nvd
CVE-2020-1646P3HIGHCVSS 7.5v17.3R3-S6v17.4R2-S7+1 more2020-07-17
CVE-2020-1646 [HIGH] CWE-159 CVE-2020-1646: On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue occurs only when the device is receiving and processing the BGP UPDATE for an EBGP peer. This issue does not occur when the device is receiving and processing the BGP UPDATE for
nvd
CVE-2021-31351P3HIGHCVSS 7.5v17.3R3-S11v18.1R3-S12+17 more2021-10-19
CVE-2021-31351 [HIGH] CWE-754 CVE-2021-31351: An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC ut
An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Servic
nvd
CVE-2021-31374P3HIGHCVSS 7.5≥ 17.3, < 17.3R3-S11≥ 17.4, < 17.4R2-S13, 17.4R3-S4+11 more2021-10-19
CVE-2021-31374 [HIGH] CWE-787 CVE-2021-31374: On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE
On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this message will create a sustained Denial of Service (DoS) condition. This issue affects both IBGP
nvd
CVE-2021-0264P3HIGHCVSS 7.5≥ 19.3, < 19.3R3-S2≥ 19.4, < 19.4R3-S2+4 more2021-04-22
CVE-2021-0264 [HIGH] CWE-703 CVE-2021-0264: A vulnerability in the processing of traffic matching a firewall filter containing a syslog action i
A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card to crash and restart, creating a Denial of Service (DoS). Continued receipt and processing of packets matching the fi
nvd
CVE-2021-0299P3HIGHCVSS 7.5≥ 19.4, < 19.4R3≥ 20.1, < 20.1R2+1 more2021-10-19
CVE-2021-0299 [HIGH] CWE-755 CVE-2021-0299: An Improper Handling of Exceptional Conditions vulnerability in the processing of a transit or direc
An Improper Handling of Exceptional Conditions vulnerability in the processing of a transit or directly received malformed IPv6 packet in Juniper Networks Junos OS results in a kernel crash, causing the device to restart, leading to a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS)
nvd
CVE-2021-0285P3HIGHCVSS 7.5≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S11+11 more2021-07-15
CVE-2021-0285 [HIGH] CWE-770 CVE-2021-0285: An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series an
An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause Interchassis Control Protocol (ICCP) interruptions, leading to an unstable control connection between the Multi-Chassis Link Aggregatio
nvd
CVE-2021-0280P3HIGHCVSS 7.5≥ 17.4, < 17.4R3-S5≥ 18.2, < 18.2R3-S8+10 more2021-07-15
CVE-2021-0280 [HIGH] CWE-665 CVE-2021-0280: Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on PTX platforms and QF
Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on PTX platforms and QFX10K Series with Paradise (PE) chipset-based line cards, ddos-protection configuration changes made from the CLI will not take effect as expected beyond the default DDoS (Distributed Denial of Service) settings in the Packet Forwarding Engine (PFE). This
nvd
CVE-2021-0230P3HIGHCVSS 7.5≥ 17.1R3, < 17.1*≥ 17.3, < 17.3R3-S11+11 more2021-04-22
CVE-2021-0230 [HIGH] CWE-400 CVE-2021-0230: On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operati
On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is consumed, the traffic will be impacted and a reboot might be required. The foll
nvd
CVE-2021-0281P3HIGHCVSS 7.5≥ 17.3, < 17.3R3-S12≥ 17.4, < 17.4R3-S5+12 more2021-07-15
CVE-2021-0281 [HIGH] CWE-754 CVE-2021-0281: On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key
On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server may cause routing process daemon (RPD) to crash and restart, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustain
nvd
CVE-2026-21916P3HIGHCVSS 7.3fixed in 23.2R2-S7≥ 23.4, < 23.4R2-S6+3 more2026-04-09
CVE-2026-21916 [HIGH] CWE-61 CVE-2026-21916: A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allow
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system.
When after a user has performed a specific 'file link ...' CLI operation, another user commits (unrelated
nvd
CVE-2026-21908P3HIGHCVSS 7.1≥ 23.2R2-S1, < 23.2R2-S5≥ 23.4R2, < 23.4R2-S6+3 more2026-01-15
CVE-2026-21908 [HIGH] CWE-416 CVE-2026-21908: A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Junipe
A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the proc
nvd
CVE-2017-2347P3HIGHCVSS 7.5v12.3X48 prior to 12.3X48-D50, 12.3X48-D55v13.3 prior to 13.3R10+7 more2017-07-17
CVE-2017-2347 [HIGH] CWE-20 CVE-2017-2347: A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS
A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM is configured. Repeated crashes of the rpd daemon can result in an extended denial of service condition for the device. The affected releases are Junos OS 12.3X48 prior to 12.3X48-D50, 12.3X48-D55; 13.3 prio
nvd
CVE-2017-10614P3HIGHCVSS 7.5v12.1X46 prior to 12.1X46-D45v12.3X48 prior to 12.3X48-D30+5 more2017-10-13
CVE-2017-10614 [HIGH] CWE-400 CVE-2017-10614: A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory an
A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption denial of service attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D45; 12.3X48 prior to 12.3X48-D30; 14.1 prior to 14.1R4-S9, 14.1R8; 14
nvd
CVE-2019-0066P3HIGHCVSS 7.5≥ 15.1, < 15.1F6-S12, 15.1R7-S2≥ 16.1, < 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S2+6 more2019-10-09
CVE-2019-0066 [HIGH] CWE-394 CVE-2019-0066: An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of
An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of Juniper Networks Junos OS allows attacker to cause a Denial of Service (DoS) condition and core the routing protocol daemon (rpd) process when a specific malformed IPv4 packet is received by the device running BGP. This malformed packet can be crafted an
nvd
CVE-2019-0075P3HIGHCVSS 7.5≥ 12.3X48, < 12.3X48-D80≥ 15.1X49, < 15.1X49-D160+5 more2019-10-09
CVE-2019-0075 [HIGH] CVE-2019-0075: A vulnerability in the srxpfe process on Protocol Independent Multicast (PIM) enabled SRX series dev
A vulnerability in the srxpfe process on Protocol Independent Multicast (PIM) enabled SRX series devices may lead to crash of the srxpfe process and an FPC reboot while processing (PIM) messages. Sustained receipt of these packets may lead to an extended denial of service condition. Affected releases are Juniper Networks Junos OS on SRX Series: 12.3X48 versions
nvd
CVE-2019-0064P3HIGHCVSS 7.5v18.2R3v18.4R2+1 more2019-10-09
CVE-2019-0064 [HIGH] CVE-2019-0064: On SRX5000 Series devices, if 'set security zones security-zone <zone> tcp-rst' is configured, the f
On SRX5000 Series devices, if 'set security zones security-zone tcp-rst' is configured, the flowd process may crash when a specific TCP packet is received by the device and triggers a new session. The process restarts automatically. However, receipt of a constant stream of these TCP packets may result in an extended Denial of Service (DoS) condition on the devi
nvd