cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 25 of 34
CVE-2025-30646P4MEDIUMCVSS 6.5fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-04-09
CVE-2025-30646 [MEDIUM] CWE-195 CVE-2025-30646: A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) o A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS). Continued recei
nvd
CVE-2025-21602P4MEDIUMCVSS 6.5≥ 21.4, < 21.4R3-S9≥ 22.2, < 22.2R3-S5+5 more2025-01-09
CVE-2025-21602 [MEDIUM] CWE-755 CVE-2025-21602: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continuous receipt and processing of this pack
nvd
CVE-2022-22182P4MEDIUMCVSS 6.1≥ 12.3, < 12.3R12-S19≥ 15.1, < 15.1R7-S10+12 more2022-04-14
CVE-2022-22182 [MEDIUM] CWE-79 CVE-2022-22182: A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S19; 15.1 versions prior t
nvd
CVE-2018-0060P4MEDIUMCVSS 5.9≥ 12.1X46, < 12.1X46-D40≥ 12.3X48, < 12.3X48-D20+7 more2018-10-10
CVE-2018-0060 [MEDIUM] CWE-20 CVE-2018-0060: An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of Service to the dcd process and interfaces and connected clients when the Junos device is requesting an IP address for itself. Junos devices are not vulnerable to this issue when not configured to use DHCP
nvd
CVE-2020-1629P4MEDIUMCVSS 5.9≥ 16.1, < 16.1R7-S6≥ 16.2, < 16.2R2-S11+12 more2020-04-08
CVE-2020-1629 [MEDIUM] CWE-366 CVE-2020-1629: A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol da A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 ve
nvd
CVE-2017-10621P4MEDIUMCVSS 5.3v12.1X46 prior to 12.1X46-D71v12.3X48 prior to 12.3X48-D50+8 more2017-10-13
CVE-2017-10621 [MEDIUM] CWE-400 CVE-2017-10621: A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unau A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9; 14.1X53 prior to 14.1X53-D50; 14.2 prior to 14.2R7-S9, 14.2R8; 15.1 prior
nvd
CVE-2017-10604P4MEDIUMCVSS 5.3v12.1X46 prior to 12.1X46-D65v12.3X48 prior to 12.3X48-D45+1 more2017-07-17
CVE-2017-10604 [MEDIUM] CWE-307 CVE-2017-10604: When the device is configured to perform account lockout with a defined period of time, any unauthen When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device is in cluster mode, and a cluster sync or failover operation occurs, then there will be errors associated with sy
nvd
CVE-2022-22204P4MEDIUMCVSS 5.3≥ 20.4, < 20.4R3-S2≥ 21.1, < 21.1R3-S2+3 more2022-07-20
CVE-2022-22204 [MEDIUM] CWE-401 CVE-2022-22204: An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service (DoS). On all MX and SRX platforms, if the SIP ALG is enabled, receipt of a specific SIP pa
nvd
CVE-2024-21596P4MEDIUMCVSS 5.3fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S7+8 more2024-01-12
CVE-2024-21596 [MEDIUM] CWE-122 CVE-2024-21596: A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). If an attacker sends a specific BGP UPDATE message to the device, this will cause a memory overwrite and therefore an RPD crash and res
nvd
CVE-2024-30409P4MEDIUMCVSS 5.3≥ 22.1, < 22.1R1-S2, 22.1R22024-04-12
CVE-2024-30409 [MEDIUM] CWE-754 CVE-2024-30409: An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Jun An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to crash, leading to a limited Denial of Service. This issue affects Juniper Networks Junos O
nvd
CVE-2024-30391P4MEDIUMCVSS 4.8fixed in 20.4R3-S7≥ 21.1, < 21.1R3+2 more2024-04-12
CVE-2024-30391 [MEDIUM] CWE-306 CVE-2024-30391: A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) o A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device. If a device is configured with IPsec authentication algorithm
nvd
CVE-2022-22203P4MEDIUMCVSS 6.5≥ 19.4, < 19.4R3-S52022-07-20
CVE-2022-22203 [MEDIUM] CWE-697 CVE-2022-22203: An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthe An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc process will crash followed by the FPC reboot upon receipt of a specific hostbound packet. Continued receipt of these specific packets w
nvd
CVE-2022-22154P4MEDIUMCVSS 6.8≥ 16.1R1, < 16.1*≥ 18.4, < 18.4R3-S10+2 more2022-01-19
CVE-2022-22154 [MEDIUM] CWE-642 CVE-2022-22154: In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes to the cabling of the device to cause a denial of service (DoS). An SD can get rebooted and subsequently controlled by an Aggregati
nvd
CVE-2021-0215P4MEDIUMCVSS 6.5≥ 14.1X53, < 14.1X53-D54≥ 15.1X49, < 15.1X49-D240+13 more2021-01-15
CVE-2021-0215 [MEDIUM] CWE-400 CVE-2021-0215: On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory l On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator port interface flaps which can lead to other processes, such as the pfex process, responsible for packet forwarding, to crash and restart. An administrator can use the following CLI command to monitor the s
nvd
CVE-2021-0221P4MEDIUMCVSS 6.5≥ unspecified, < 17.3R3-S10≥ 17.4, < 17.4R2-S12, 17.4R3-S3+10 more2021-01-15
CVE-2021-0221 [MEDIUM] CWE-703 CVE-2021-0221: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase abnormally, ultimately leading to a Denial of Service (DoS) in packet processing. The following command could be use
nvd
CVE-2021-0267P4MEDIUMCVSS 6.5≥ 19.4, < 19.4R3-S1≥ 20.1, < 20.1R2-S1, 20.1R3+2 more2021-04-22
CVE-2021-0267 [MEDIUM] CWE-20 CVE-2021-0267: An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending a crafted DHCP packet to the device thereby crashing the jdhcpd DHCP service. This is typically configured for Broadband Subscriber Sessions. Continued rec
nvd
CVE-2022-22249P4MEDIUMCVSS 6.5≥ unspecified, < 15.1R7-S13≥ 19.1, < 19.1R3-S9+10 more2022-10-18
CVE-2022-22249 [MEDIUM] CWE-664 CVE-2022-22249: An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory corruption causes one or more FPCs to crash and reboot. These MAC moves can b
nvd
CVE-2021-31362P4MEDIUMCVSS 6.5≥ unspecified, < 18.2R3-S8≥ 18.3, < 18.3R3-S5+9 more2021-10-19
CVE-2021-31362 [MEDIUM] CWE-693 CVE-2021-31362: A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Ju A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading to a Denial of Service (DoS) condition. Continued receipted of these spoofed PDUs will cre
nvd
CVE-2021-31370P4MEDIUMCVSS 6.5≥ unspecified, < 17.3R3-S12≥ 17.4, < 17.4R3-S5+11 more2021-10-19
CVE-2021-31370 [MEDIUM] CWE-184 CVE-2021-31370: An Incomplete List of Disallowed Inputs vulnerability in Packet Forwarding Engine (PFE) of Juniper N An Incomplete List of Disallowed Inputs vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an adjacent unauthenticated attacker which sends a high rate of specific multicast traffic to cause control traffic received from the network to be dropped. This will impact control protocols
nvd
CVE-2021-31366P4MEDIUMCVSS 6.5≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S12+14 more2021-10-19
CVE-2021-31366 [MEDIUM] CWE-252 CVE-2021-31366: An Unchecked Return Value vulnerability in the authd (authentication daemon) of Juniper Networks Jun An Unchecked Return Value vulnerability in the authd (authentication daemon) of Juniper Networks Junos OS on MX Series configured for subscriber management / BBE allows an adjacent attacker to cause a crash by sending a specific username. This impacts authentication, authorization, and accounting (AAA) services on the MX devices and leads to a Denia
nvd
Juniper Networks Junos Os vulnerabilities | cvebase