Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 22 of 34
CVE-2025-30657P4MEDIUMCVSS 5.3fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+3 more2025-04-09
CVE-2025-30657 [MEDIUM] CWE-116 CVE-2025-30657: An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD)
An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When a device configured for flow-monitoring receives a specific BGP update message, it is correctly processed internally by the routing
nvd
CVE-2020-1618P4MEDIUMCVSS 6.8≥ 14.1X53, < 14.1X53-D53≥ 15.1, < 15.1R7-S4+9 more2020-04-08
CVE-2020-1618 [MEDIUM] CWE-288 CVE-2020-1618: On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user conne
On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot after performing device factory reset using the command “request system zeroize”; or • A temporary moment during the
nvd
CVE-2024-47503P4MEDIUMCVSS 6.5fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S11+5 more2024-10-11
CVE-2024-47503 [MEDIUM] CWE-754 CVE-2024-47503: An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated and logically adjacent attacker to cause a Denial-of-Service (DoS).
If in a multicast scenario a sequence of
specific PIM packets is received, this will caus
nvd
CVE-2024-39541P4MEDIUMCVSS 6.5≥ 22.4, < 22.4R3-S1≥ 23.2, < 23.2R2+1 more2024-07-11
CVE-2024-39541 [MEDIUM] CWE-755 CVE-2024-39541: An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
When conflicting information (IP or ISO addresses) about a node is added to the Traffic Engineering (TE) database and the
nvd
CVE-2024-39543P4MEDIUMCVSS 6.5fixed in 21.2R3-S8≥ 21.4, < 21.4R3-S8+5 more2024-07-11
CVE-2024-39543 [MEDIUM] CWE-120 CVE-2024-39543: A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of J
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Continued receipt and processing of this
nvd
CVE-2023-22414P4MEDIUMCVSS 6.5≥ 20.2, < 20.2R3-S6≥ 20.3, < 20.3R3-S6+6 more2023-01-13
CVE-2023-22414 [MEDIUM] CWE-401 CVE-2023-22414: A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC
A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a heap memory leak and leading to FPC crash. On all Junos PTX Series and QFX10000 Series, when specific EVPN VXLAN M
nvd
CVE-2024-21618P4MEDIUMCVSS 6.5≥ 21.4, < 21.4R3-S4≥ 22.1, < 22.1R3-S4+4 more2024-04-12
CVE-2024-21618 [MEDIUM] CWE-788 CVE-2024-21618: An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daem
An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, when LLDP is enabled on a specific interface, and a malformed
nvd
CVE-2025-52955P4MEDIUMCVSS 6.5fixed in 21.2R3-S9≥ 21.4, < 21.4*+5 more2025-07-11
CVE-2025-52955 [MEDIUM] CWE-131 CVE-2025-52955: An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Junipe
An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a memory corruption that leads to a rpd crash.
When
the logical interface using a routing instance flaps continuously, specific updates are sent to the jfl
nvd
CVE-2025-52952P4MEDIUMCVSS 6.5fixed in 22.2R3-S1≥ 22.4, < 22.4R22025-07-11
CVE-2025-52952 [MEDIUM] CWE-787 CVE-2025-52952: An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Ne
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS).
Continued r
nvd
CVE-2024-30388P4MEDIUMCVSS 6.5≥ 20.4R3-S4, < 20.4R3-S8≥ 21.2R3-S2, < 21.2R3-S6+5 more2024-04-12
CVE-2024-30388 [MEDIUM] CWE-653 CVE-2024-30388: An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
If a specific malformed LACP packet is received by a QFX5000 Series, or an EX4400, EX4100 or EX4650 Series dev
nvd
CVE-2026-33780P4MEDIUMCVSS 6.5fixed in 22.4R3-S5≥ 23.2, < 23.2R2-S3+2 more2026-04-09
CVE-2026-33780 [MEDIUM] CWE-401 CVE-2026-33780: A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning D
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).
In an EVPN-MPLS scenario, routes learned from remote multi-homed Pro
nvd
CVE-2025-21595P4MEDIUMCVSS 6.5fixed in 21.2R3-S7≥ 21.4, < 21.4R3-S4+3 more2025-04-09
CVE-2025-21595 [MEDIUM] CWE-401 CVE-2025-21595: A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause an FPC to crash, leading to Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, in an EVPN-VXLAN scenario, when specific
nvd
CVE-2026-21909P4MEDIUMCVSS 6.5≥ 23.2, < 23.2R2≥ 23.4, < 23.4R1-S2, 23.4R2+1 more2026-01-15
CVE-2026-21909 [MEDIUM] CWE-401 CVE-2026-21909: A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (r
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all ava
nvd
CVE-2025-21593P4MEDIUMCVSS 6.5fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-01-09
CVE-2025-21593 [MEDIUM] CWE-664 CVE-2025-21593: An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon
An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS).
On devices with SRv6 (Segment Routing over IPv6) enabled, an attacker can send a malformed BGP UPDATE packet w
nvd
CVE-2024-30387P4MEDIUMCVSS 6.5fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S5+6 more2024-04-12
CVE-2024-30387 [MEDIUM] CWE-820 CVE-2024-30387: A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Ju
A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
If an interface flaps while the system gathers statistics on that interface, two processes simultaneously access a shared resource which lea
nvd
CVE-2018-0002P4MEDIUMCVSS 5.9≥ 12.1X46, < 12.1X46-D60≥ 12.3X48, < 12.3X48-D35+7 more2018-01-10
CVE-2018-0002 [MEDIUM] CWE-119 CVE-2018-0002: On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP respon
On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed through the device results in memory corruption leading to a flowd daemon crash. Sustained crafted response packets lead to repeated crashes of the flowd daemon which results in an extended Denial of Service condition. Affected relea
nvd
CVE-2017-10618P4MEDIUMCVSS 5.9v13.3 prior to 13.3R10-S2v14.1 prior to 14.1R8-S4, 14.1R9+11 more2017-10-13
CVE-2017-10618 [MEDIUM] CVE-2017-10618: When the 'bgp-error-tolerance' feature â€" designed to help mitigate remote session resets
When the 'bgp-error-tolerance' feature â€" designed to help mitigate remote session resets from malformed path attributes â€" is enabled, a BGP UPDATE containing a specifically crafted set of transitive attributes can cause the RPD routing process to crash and restart. Devices with BGP enabled that do not have 'bgp-error-tolerance' configured are not vulner
nvd
CVE-2021-0205P4MEDIUMCVSS 5.8≥ 17.3, < 17.3R3-S10≥ 17.4, < 17.4R3-S3+10 more2021-01-15
CVE-2021-0205 [MEDIUM] CWE-284 CVE-2021-0205: When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series wit
When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to block unexpected traffic. This issue affects only IPv6 prefixes when used as source and destination. This issue affect
nvd
CVE-2021-0263P4MEDIUMCVSS 5.9≥ 18.2, < 18.2R3-S7≥ 18.3, < 18.3R3-S4+8 more2021-04-22
CVE-2021-0263 [MEDIUM] CWE-19 CVE-2021-0263: A Data Processing vulnerability in the Multi-Service process (multi-svcs) on the FPC of Juniper Netw
A Data Processing vulnerability in the Multi-Service process (multi-svcs) on the FPC of Juniper Networks Junos OS on the PTX Series routers may lead to the process becoming unresponsive, ultimately affecting traffic forwarding, allowing an attacker to cause a Denial of Service (DoS) condition . The Multi-Service Process running on the FPC is responsibl
nvd
CVE-2022-22169P4MEDIUMCVSS 5.9≥ 15.1, < 15.1R7-S11≥ 18.3, < 18.3R3-S6+11 more2022-01-19
CVE-2022-22169 [MEDIUM] CWE-665 CVE-2022-22169: An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any Grace-LSA received in OSPFv3 causi
nvd