Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 26 of 34
CVE-2021-31363P4MEDIUMCVSS 6.5≥ 19.2R2, < 19.2*≥ 19.3, < 19.3R2-S6, 19.3R3-S2+4 more2021-10-19
CVE-2021-31363 [MEDIUM] CWE-835 CVE-2021-31363: In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing prot
In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause high load on RPD which in turn may lead to routing protocol flaps. If a system with sensor-based-stats enabled receives a specific
nvd
CVE-2021-31365P4MEDIUMCVSS 6.5≥ unspecified, < 15.1R7-S7≥ 16.1, < 16.1R7-S8+34 more2021-10-19
CVE-2021-31365 [MEDIUM] CWE-400 CVE-2021-31365: An Uncontrolled Resource Consumption vulnerability in Juniper Networks Junos OS on EX2300, EX3400 an
An Uncontrolled Resource Consumption vulnerability in Juniper Networks Junos OS on EX2300, EX3400 and EX4300 Series platforms allows an adjacent attacker sending a stream of layer 2 frames will trigger an Aggregated Ethernet (AE) interface to go down and thereby causing a Denial of Service (DoS). By continuously sending a stream of specific layer 2
nvd
CVE-2022-22196P4MEDIUMCVSS 6.5≥ 19.3, < 19.3R3-S4≥ 19.4, < 19.4R2-S6, 19.4R3-S6+6 more2022-04-14
CVE-2022-22196 [MEDIUM] CWE-754 CVE-2022-22196: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS). The rpd CPU spikes to 100% after a malformed ISIS TLV has been received which
nvd
CVE-2022-22179P4MEDIUMCVSS 6.5≥ 17.4R1, < 17.4*≥ 18.4, < 18.4R3-S10+11 more2022-01-19
CVE-2022-22179 [MEDIUM] CWE-20 CVE-2022-22179: A Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper
A Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). In a scenario where DHCP relay or local server is configured the problem can be triggered if
nvd
CVE-2022-22191P4MEDIUMCVSS 6.5≥ unspecified, < 15.1R7-S12≥ 18.4, < 18.4R2-S10, 18.4R3-S11+11 more2022-04-14
CVE-2022-22191 [MEDIUM] CWE-410 CVE-2022-22191: A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juni
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to trigger a PFEMAN watchdog timeout, causing the Packet Forwarding Engine (PFE) to crash and restart. After the r
nvd
CVE-2022-22172P4MEDIUMCVSS 6.5≥ 18.4R2-S4, < 18.4*≥ 19.2, < 19.2R1-S8, 19.2R3-S4+8 more2022-01-19
CVE-2022-22172 [MEDIUM] CWE-401 CVE-2022-22172: A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). This issue occurs when spec
nvd
CVE-2022-22176P4MEDIUMCVSS 6.5≥ unspecified, < 15.1R7-S11≥ 13.2R1, < 13.2*+12 more2022-01-19
CVE-2022-22176 [MEDIUM] CWE-1286 CVE-2022-22176: An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (j
An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If option-82 is configured in a DHCP snooping / -security scenario, jdhc
nvd
CVE-2022-22160P4MEDIUMCVSS 6.5≥ unspecified, < 18.4R3-S10≥ 16.1R1, < 16.1*+10 more2022-01-19
CVE-2022-22160 [MEDIUM] CWE-391 CVE-2022-22160: An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Net
An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). In a subscriber management / broadband edge environment if a single session group configuration contains dual-stack and a pp0 interfa
nvd
CVE-2024-21600P4MEDIUMCVSS 6.5fixed in 20.4R3-S8≥ 21.1, < 21.1R3-S4+5 more2024-01-12
CVE-2024-21600 [MEDIUM] CWE-76 CVE-2024-21600: An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding En
An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
When MPLS packets are meant to be sent to a flexible tunnel interface (FTI) and if the FTI tunnel is down, these will h
nvd
CVE-2022-22214P4MEDIUMCVSS 6.5≥ unspecified, < 12.3R12-S21≥ 15.1, < 15.1R7-S10+12 more2022-07-20
CVE-2022-22214 [MEDIUM] CWE-20 CVE-2022-22214: An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent attacker to cause a PFE crash and thereby a Denial of Service (DoS). An FPC will crash and reboot after receiving a specific transit IPv6 packet over MPLS. Continued receipt of this packet will create a
nvd
CVE-2022-22210P4MEDIUMCVSS 6.5≥ 20.3, < 20.3R3-S3≥ 20.4, < 20.4R3-S2+1 more2022-07-20
CVE-2022-22210 [MEDIUM] CWE-476 CVE-2022-22210: A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks J
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). On QFX5K Series and MX Series, when the PFE receives a specific VxLAN packet the Layer 2 Address Learning Manager (L2ALM) process w
nvd
CVE-2023-1697P4MEDIUMCVSS 6.5≥ unspecified, < 19.4R3-S10≥ 20.1R1, < 20.1*+9 more2023-04-17
CVE-2023-1697 [MEDIUM] CWE-230 CVE-2023-1697: An Improper Handling of Missing Values vulnerability in the Packet Forwarding Engine (PFE) of Junipe
An Improper Handling of Missing Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a dcpfe process core and thereby a Denial of Service (DoS). Continued receipt of these specific frames will cause a sustained Denial of Service condition. This issue occurs when a
nvd
CVE-2022-22226P4MEDIUMCVSS 6.5≥ 17.1R1, < 17.1*≥ 17.2R1, < 17.2*+13 more2022-10-18
CVE-2022-22226 [MEDIUM] CWE-789 CVE-2022-22226: In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vu
In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated adjacently located attacker sending specific packets to cause a Denial of Service (DoS) condition by crashing one or more PFE's when they are rece
nvd
CVE-2022-22230P4MEDIUMCVSS 6.5≥ 19.2, < 19.2R3-S6≥ 19.3R2, < 19.3*+9 more2022-10-18
CVE-2022-22230 [MEDIUM] CWE-20 CVE-2022-22230: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause DoS (Denial of Service). If another router generates more than one specific valid OSPFv3 LSA then rpd will crash while processing these LSAs. This issue only affects syst
nvd
CVE-2022-22224P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S5+7 more2022-10-18
CVE-2022-22224 [MEDIUM] CWE-703 CVE-2022-22224: An Improper Check or Handling of Exceptional Conditions vulnerability in the processing of a malform
An Improper Check or Handling of Exceptional Conditions vulnerability in the processing of a malformed OSPF TLV in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause the periodic packet management daemon (PPMD) process to go into an infinite loop, which in turn can cause protocols and functions relian
nvd
CVE-2023-28974P4MEDIUMCVSS 6.5≥ unspecified, < 19.4R3-S11≥ 20.2, < 20.2R3-S7+9 more2023-04-17
CVE-2023-28974 [MEDIUM] CWE-754 CVE-2023-28974: An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Net
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to the device is received from a subs
nvd
CVE-2023-28959P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S10≥ 19.4, < 19.4R3-S11+9 more2023-04-17
CVE-2023-28959 [MEDIUM] CWE-703 CVE-2023-28959: An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Junipe
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on QFX10002 allows an unauthenticated, adjacent attacker on the local broadcast domain sending a malformed packet to the device, causing all PFEs other than the inbound PFE to wedge and to eventually restart, resulting in a Denial
nvd
CVE-2023-36849P4MEDIUMCVSS 6.5≥ 21.4, < 21.4R3-S3≥ 22.1, < 22.1R3-S3+2 more2023-07-14
CVE-2023-36849 [MEDIUM] CWE-703 CVE-2023-36849: An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protoco
An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS).
When a malformed LLDP packet is received, l2cpd will crash and restart. The impact of the l2cpd crash
nvd
CVE-2023-36848P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S10≥ 19.2, < 19.2R3-S7+14 more2023-07-14
CVE-2023-36848 [MEDIUM] CWE-232 CVE-2023-36848: An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPM
An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS).
When a malformed CFM packet is received, it leads to an FPC crash. Continued receipt of these
nvd
CVE-2023-36834P4MEDIUMCVSS 6.5≥ 20.1, < 20.1*≥ 20.2, < 20.2R3-S7+9 more2023-07-14
CVE-2023-36834 [MEDIUM] CWE-372 CVE-2023-36834: An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juni
An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX 4600 and SRX 5000 Series allows an adjacent attacker to cause a Denial of Service (DoS).
If an SRX is configured in L2 transparent mode the receipt of a specific genuine packet can cause a single Packet Processing Engines
nvd