Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 19 of 34
CVE-2026-57021P3MEDIUMCVSS 5.3≥ 23.2, < 23.2R2-S7≥ 23.4, < 23.4R2-S8+4 more2026-07-09
CVE-2026-57021 [MEDIUM] CWE-787 CVE-2026-57021: An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS o
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted re
nvd
CVE-2021-0235P4HIGHCVSS 7.3≥ 18.3R1, < 18.3*≥ 18.4R1, < 18.4*+8 more2021-04-22
CVE-2021-0235 [HIGH] CWE-276 CVE-2021-0235: On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tena
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to incorrect permission scheme assigned to tenant system administrators, a tenant system administrator may inadvertently send their network traffic to one or more tenants while concurrently modifying the overa
nvd
CVE-2021-0246P4HIGHCVSS 7.3≥ 18.4, < 18.4R2≥ 19.1, < 19.1R2+1 more2021-04-22
CVE-2021-0246 [HIGH] CWE-276 CVE-2021-0246: On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks Junos OS, due to incorrect default permissions assigned to tenant system administrators a tenant system administrator may inadvertently send their network traffic to one or more tenants while concurrently modifying the overall device sy
nvd
CVE-2019-0073P4HIGHCVSS 7.1≥ 15.1X49, < 15.1X49-D180≥ 17.3, < 17.3R3-S7+5 more2019-10-09
CVE-2019-0073 [HIGH] CWE-732 CVE-2019-0073: The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may h
The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file permissions. This may allow another user on the Junos OS device with shell access to read them. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D180; 17.3 versions prior to 17.3R3-S7; 17.4 versions prior t
nvd
CVE-2024-39556P4HIGHCVSS 7.0fixed in 21.4R3-S7≥ 22.1, < 22.1R3-S6+5 more2024-07-10
CVE-2024-39556 [HIGH] CWE-121 CVE-2024-39556: A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos
A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution.
By exploiting the 'set security certificates' comma
nvd
CVE-2025-59957P3MEDIUMCVSS 6.8fixed in 21.4R3≥ 22.2, < 22.2R3-S32025-10-09
CVE-2025-59957 [MEDIUM] CWE-346 CVE-2025-59957: An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos
An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system.
When a device isn't configured with a root password, an attacker can modif
nvd
CVE-2021-0236P4MEDIUMCVSS 6.5≥ 18.4, < 18.4R1-S8, 18.4R2-S7, 18.4R3-S7≥ 19.1, < 19.1R2-S2, 19.1R3-S4+6 more2021-04-22
CVE-2021-0236 [MEDIUM] CWE-754 CVE-2021-0236: Due to an improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Juno
Due to an improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved the Routing Protocol Daemon (RPD) service, upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, crashes and restarts causing a Denial of Service (DoS). Continued receipt and processing of thi
nvd
CVE-2025-30650P3MEDIUMCVSS 6.7fixed in 22.4R3-S8≥ 23.2, < 23.2R2-S6+4 more2026-04-08
CVE-2025-30650 [MEDIUM] CWE-306 CVE-2025-30650: A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networ
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.
This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:
* MPC7, MPC8, MPC9, MPC10, MPC11
* LC2101, LC2103
nvd
CVE-2025-52960P3MEDIUMCVSS 5.9fixed in 22.4R3-S7≥ 23.2, < 23.2R2-S4+2 more2025-10-09
CVE-2025-52960 [MEDIUM] CWE-120 CVE-2025-52960: A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol
A Buffer Copy without Checking Size of Input vulnerability in the
Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
When memory utilization is high, and specific SIP packets are received, flowd/mspmand crashes. While
nvd
CVE-2026-57030P4MEDIUMCVSS 5.9≥ 24.2, < 24.2R2-S3≥ 24.4, < 24.4R2-S1+1 more2026-07-09
CVE-2026-57030 [MEDIUM] CWE-362 CVE-2026-57030: A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulner
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
As part of the stateful traffic processing on SRX Series devices flows are
nvd
CVE-2021-0219P4MEDIUMCVSS 6.7≥ unspecified, < 17.3R3-S10≥ 17.4, < 17.4R2-S12, 17.4R3-S3+11 more2021-01-15
CVE-2021-0219 [MEDIUM] CWE-78 CVE-2021-0219: A command injection vulnerability in install package validation subsystem of Juniper Networks Junos
A command injection vulnerability in install package validation subsystem of Juniper Networks Junos OS that may allow a locally authenticated attacker with privileges to execute commands with root privilege. To validate a package in Junos before installation, an administrator executes the command 'request system software add validate-on-host' via the CL
nvd
CVE-2021-31386P4MEDIUMCVSS 5.9≥ 12.3, < 12.3R12-S20≥ 15.1, < 15.1R7-S11+12 more2021-10-19
CVE-2021-31386 [MEDIUM] CWE-300 CVE-2021-31386: A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S20; 15.1 versions prior to 15.1R7-S11; 18.3 versions prior to 18.3
nvd
CVE-2025-52984P3MEDIUMCVSS 5.9fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-07-11
CVE-2025-52984 [MEDIUM] CWE-476 CVE-2025-52984: A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju
A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device.
When static route points to a reject next hop and a gNMI query is processed for that static route, rpd crashes and restar
nvd
CVE-2025-52982P3MEDIUMCVSS 5.9fixed in 21.2R3-S9≥ 21.4, < 21.4*+2 more2025-07-11
CVE-2025-52982 [MEDIUM] CWE-404 CVE-2025-52982: An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS o
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When an MX Series device with an MS-MPC is configured with two or more service sets which are both processing SIP calls, a specific sequence
nvd
CVE-2024-39554P3MEDIUMCVSS 5.9≥ 21.1, < 21.1*≥ 21.2, < 21.2R3-S7+6 more2024-07-10
CVE-2024-39554 [MEDIUM] CWE-362 CVE-2024-39554: A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulner
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the
Routing Protocol Daemon (rpd)
of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash
nvd
CVE-2024-30389P3MEDIUMCVSS 5.8≥ 21.4, < 21.4R3-S62024-04-12
CVE-2024-30389 [MEDIUM] CWE-696 CVE-2024-30389: An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks
An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device.
When an output firewall filter is applied to an interface it doesn't recognize matching packets b
nvd
CVE-2024-47507P3MEDIUMCVSS 5.8fixed in 21.4R3-S6≥ 22.2, < 22.2R3-S3+1 more2024-10-11
CVE-2024-47507 [MEDIUM] CWE-754 CVE-2024-47507: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices.
When a peer sends a BGP update message which contains the aggregator attribute with an
nvd
CVE-2023-28963P4MEDIUMCVSS 5.3≥ unspecified, < 19.1R3-S10≥ 19.2, < 19.2R3-S7+13 more2023-04-17
CVE-2023-28963 [MEDIUM] CWE-287 CVE-2023-28963: An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Ne
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.1R3-S10; 19.2 versions prior to 19.2R3-S7; 19.3 vers
nvd
CVE-2018-0004P4MEDIUMCVSS 6.5≥ 12.1X46, < 12.1X46-D50≥ 12.3X48, < 12.3X48-D30+7 more2018-01-10
CVE-2018-0004 [MEDIUM] CWE-400 CVE-2018-0004: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the device. This affects one or more threads and conversely one or more running processes running on the system.
nvd
CVE-2018-0034P4MEDIUMCVSS 5.9≥ 12.3X48, < 12.3X48-D70≥ 15.1X49, < 15.1X49-D140+13 more2018-07-11
CVE-2018-0034 [MEDIUM] CWE-20 CVE-2018-0034: A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows
A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending a crafted IPv6 packet to the system. This issue is limited to systems which receives IPv6 DHCP packets on a system configured for DHCP processing using the JDHCPD daemon. This issue does not affect IPv4 D
nvd