Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 17 of 34
CVE-2019-0061P3HIGHCVSS 7.8≥ 15.1X49, < 15.1X49-D171, 15.1X49-D180≥ 15.1X53, < 15.1X53-D496, 15.1X53-D69+10 more2019-10-09
CVE-2019-0061 [HIGH] CWE-657 CVE-2019-0061: The management daemon (MGD) is responsible for all configuration and management operations in Junos
The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due to a misconfiguration of the internal socket, a local, authenticated user may be able to exploit this vuln
nvd
CVE-2020-1650P3HIGHCVSS 7.5v17.2R2-S7v17.3R3-S4, 17.3R3-S5+9 more2020-07-17
CVE-2020-1650 [HIGH] CVE-2020-1650: On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific pa
On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific packets may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sending these specific packets, an attacker can repeatedly bring down MS-PIC on MS-MIC/MS-MPC causing a prolonged Denial of Service. This issue affects MX Series devices using MS-PIC, MS-MI
nvd
CVE-2017-10620P3HIGHCVSS 7.4v12.1X46 prior to 12.3X46-D71v12.3X48 prior to 12.3X48-D55+1 more2017-10-13
CVE-2017-10620 [HIGH] CWE-295 CVE-2017-10620: Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before do
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X
nvd
CVE-2025-59960P3HIGHCVSS 7.4fixed in 21.2R3-S10≥ 21.4, < 21.4R3-S12+7 more2026-01-15
CVE-2025-59960 [HIGH] CWE-754 CVE-2025-59960: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (j
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server.
By default, the DHCP relay agent inserts its
nvd
CVE-2021-0231P3MEDIUMCVSS 6.5≥ 19.3, < 19.3R2-S6, 19.3R3-S1≥ 19.4, < 19.4R2-S4, 19.4R3+2 more2021-04-22
CVE-2021-0231 [MEDIUM] CWE-22 CVE-2021-0231: A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticate
A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read sensitive system files. This issue affects Juniper Networks Junos OS on SRX and vSRX Series: 19.3 versions prior to 19.3R2-S6, 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2; 20.2 versio
nvd
CVE-2022-22237P3MEDIUMCVSS 6.5≥ 21.2, < 21.2R3-S1≥ 21.3, < 21.3R2-S2, 21.3R3+2 more2022-10-18
CVE-2022-22237 [MEDIUM] CWE-287 CVE-2022-22237: An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauth
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer not configured with authentication to establish a session even if the peer is locally config
nvd
CVE-2026-21903P3MEDIUMCVSS 6.5fixed in 22.4R3-S7≥ 23.2, < 23.2R2-S4+1 more2026-01-15
CVE-2026-21903 [MEDIUM] CWE-121 CVE-2026-21903: A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Network
A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS).
Subscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart.
The issue was not
nvd
CVE-2026-21921P3MEDIUMCVSS 6.5fixed in 22.4R3-S8≥ 23.2, < 23.2R2-S5+1 more2026-01-15
CVE-2026-21921 [MEDIUM] CWE-416 CVE-2026-21921: A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Jun
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS).
When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-c
nvd
CVE-2026-21919P3MEDIUMCVSS 6.5≥ 23.4, < 23.4R2-S4≥ 24.2, < 24.2R2-S1+1 more2026-04-09
CVE-2026-21919 [MEDIUM] CWE-821 CVE-2026-21919: An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane.
When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to ha
nvd
CVE-2025-6549P3MEDIUMCVSS 6.5fixed in 21.4R3-S9≥ 22.2, < 22.2R3-S5+4 more2025-07-11
CVE-2025-6549 [MEDIUM] CWE-863 CVE-2025-6549: An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Serie
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the
Juniper Web Device Manager
(J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over
nvd
CVE-2018-0020P3HIGHCVSS 7.5≥ 14.1X53, < 14.1X53-D47≥ 15.1, < 15.1F6-S10, 15.1R4-S9, 15.1R6-S6, 15.1R7+12 more2018-04-11
CVE-2018-0020 [HIGH] CWE-20 CVE-2018-0020: Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing proces
Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a repeated malformed BGP UPDATEs can result in an extended denial of service condition for the device. This malformed BGP UPDATE does not propagate to other BGP peers. Affected releases are Juniper Networks Juno
nvd
CVE-2017-2314P3HIGHCVSS 7.5v12.3 prior to 12.3R12-S4, 12.3R13, 12.3R3-S4v12.3X48 prior to 12.3X48-D50+8 more2017-07-17
CVE-2017-2314 [HIGH] CWE-20 CVE-2017-2314: Receipt of a malformed BGP OPEN message may cause the routing protocol daemon (rpd) process to crash
Receipt of a malformed BGP OPEN message may cause the routing protocol daemon (rpd) process to crash and restart. By continuously sending specially crafted BGP OPEN messages, an attacker can repeatedly crash the rpd process causing prolonged denial of service. No other Juniper Networks products or platforms are affected by this issue. Affected releases a
nvd
CVE-2019-0019P3HIGHCVSS 7.5≥ 16.1, < 16.1R7-S4, 16.1R7-S5≥ 16.2, < 16.2R2-S9, 16.2R3+9 more2019-04-10
CVE-2019-0019 [HIGH] CWE-404 CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9,
nvd
CVE-2017-10608P3HIGHCVSS 7.5v12.1X46 prior to 12.1X46-D55v12.3X48 prior to 12.3X48-D32, 12.3X48-D35+1 more2017-10-13
CVE-2017-10608 [HIGH] CWE-400 CVE-2017-10608: Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash wh
Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated denial of service against the target. Repeated traffic in a cluster may cause repeated flip-fl
nvd
CVE-2017-10607P3HIGHCVSS 7.5v16.1 prior to 16.1R22017-10-13
CVE-2017-10607 [HIGH] CVE-2017-10607: Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the r
Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP
nvd
CVE-2021-0244P3HIGHCVSS 7.4≥ 14.1X53, < 14.1X53-D49≥ 15.1, < 15.1R7-S6+12 more2021-04-22
CVE-2021-0244 [HIGH] CWE-362 CVE-2021-0244: A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Net
A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the storm-control feature on devices. This issue is a corner case and only occurs during specific actions taken by an admi
nvd
CVE-2025-21591P3HIGHCVSS 7.4≥ 23.1, < 23.2R2-S3≥ 23.4, < 23.4R2-S3+1 more2025-04-09
CVE-2025-21591 [HIGH] CWE-805 CVE-2025-21591: A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks J
A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to crash creating a Denial of Service (DoS) condition.
Continuous receipt of these DHCP packets usin
nvd
CVE-2025-30661P3HIGHCVSS 7.3≥ 23.2, < 23.2R2-S4≥ 23.4, < 23.4R2-S5+2 more2025-07-11
CVE-2025-30661 [HIGH] CWE-732 CVE-2025-30661: An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processin
An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation.
A local user with access to the local file system can copy a script to the router in a way that will be execu
nvd
CVE-2026-57032P3MEDIUMCVSS 6.5fixed in 23.2R2-S7≥ 23.4, < 23.4R2-S8+2 more2026-07-09
CVE-2026-57032 [MEDIUM] CWE-236 CVE-2026-57032: An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).
If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX
nvd
CVE-2021-0217P3HIGHCVSS 7.4≥ 17.4, < 17.4R3-S3≥ 18.1R3-S6, < 18.1*+9 more2021-01-15
CVE-2021-0217 [HIGH] CWE-119 CVE-2021-0217: A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Ser
A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS with DHCP local/relay server configured may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability may cause traffic to stop being forwarded, or to c
nvd