Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 27 of 34
CVE-2023-28974P4MEDIUMCVSS 6.5≥ unspecified, < 19.4R3-S11≥ 20.2, < 20.2R3-S7+9 more2023-04-17
CVE-2023-28974 [MEDIUM] CWE-754 CVE-2023-28974: An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Net
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to the device is received from a subs
nvd
CVE-2023-28959P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S10≥ 19.4, < 19.4R3-S11+9 more2023-04-17
CVE-2023-28959 [MEDIUM] CWE-703 CVE-2023-28959: An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Junipe
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on QFX10002 allows an unauthenticated, adjacent attacker on the local broadcast domain sending a malformed packet to the device, causing all PFEs other than the inbound PFE to wedge and to eventually restart, resulting in a Denial
nvd
CVE-2022-22230P4MEDIUMCVSS 6.5≥ 19.2, < 19.2R3-S6≥ 19.3R2, < 19.3*+9 more2022-10-18
CVE-2022-22230 [MEDIUM] CWE-20 CVE-2022-22230: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause DoS (Denial of Service). If another router generates more than one specific valid OSPFv3 LSA then rpd will crash while processing these LSAs. This issue only affects syst
nvd
CVE-2022-22224P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S5+7 more2022-10-18
CVE-2022-22224 [MEDIUM] CWE-703 CVE-2022-22224: An Improper Check or Handling of Exceptional Conditions vulnerability in the processing of a malform
An Improper Check or Handling of Exceptional Conditions vulnerability in the processing of a malformed OSPF TLV in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause the periodic packet management daemon (PPMD) process to go into an infinite loop, which in turn can cause protocols and functions relian
nvd
CVE-2024-21605P4MEDIUMCVSS 6.5≥ 21.2R3-S3, < 21.2R3-S6≥ 22.1R3, < 22.1R3-S4+4 more2024-04-12
CVE-2024-21605 [MEDIUM] CWE-668 CVE-2024-21605: An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Junip
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
Specific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the de
nvd
CVE-2024-21609P4MEDIUMCVSS 6.5fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S7+7 more2024-04-12
CVE-2024-21609 [MEDIUM] CWE-401 CVE-2024-21609: A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Junip
A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels to cause a Denial of Service (DoS).
If specific values for the IPsec parameters local-ip, r
nvd
CVE-2022-22238P4MEDIUMCVSS 6.5≥ unspecified, < 19.2R3-S6≥ 19.3, < 19.3R3-S6+8 more2022-10-18
CVE-2022-22238 [MEDIUM] CWE-754 CVE-2022-22238: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When an incoming RESV message corresponding to a protected LSP is malformed it causes an incorrect internal state
nvd
CVE-2024-21613P4MEDIUMCVSS 6.5fixed in 21.2R3-S3≥ 21.3, < 21.3R3-S5+3 more2024-01-12
CVE-2024-21613 [MEDIUM] CWE-401 CVE-2024-21613: A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD)
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, when traffic engineering is enabled for OSPF or I
nvd
CVE-2024-21587P4MEDIUMCVSS 6.5fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S7+7 more2024-01-12
CVE-2024-21587 [MEDIUM] CWE-755 CVE-2024-21587: An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber manag
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS).
nvd
CVE-2025-52947P4MEDIUMCVSS 6.5fixed in 21.2R3-S92025-07-11
CVE-2025-52947 [MEDIUM] CWE-755 CVE-2025-52947: An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks
An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an interface, leading to a Denial of Service (DoS).
On ACX1000, ACX1100, ACX2000, ACX2100, ACX2200, ACX4000, ACX504
nvd
CVE-2024-39517P4MEDIUMCVSS 6.5fixed in 21.2R3-S8≥ 21.4, < 21.4R3-S7+6 more2024-07-10
CVE-2024-39517 [MEDIUM] CWE-754 CVE-2024-39517: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learnin
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).
In an EVPN/VXLAN scenario, when a high amount specific Layer 2 packets are processed by the device, it c
nvd
CVE-2024-39514P4MEDIUMCVSS 6.5fixed in 20.4R3-S10≥ 21.4, < 21.4R3-S6+5 more2024-07-10
CVE-2024-39514 [MEDIUM] CWE-703 CVE-2024-39514: An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon
An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
An attacker can send specific traffic to the device, which causes the rpd to crash and restart. Continued receipt o
nvd
CVE-2025-30647P4MEDIUMCVSS 6.5fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-04-09
CVE-2025-30647 [MEDIUM] CWE-401 CVE-2025-30647: A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).
In a subscriber management scenario, login/logout activity triggers a memory leak, and the leaked memory gradually incremen
nvd
CVE-2017-2346P4MEDIUMCVSS 5.9v14.1X55 from 14.1X55-D30 prior to 14.1X55-D35v14.2R from 14.2R7 prior to 14.2R7-S4, 14.2R8+2 more2017-07-17
CVE-2017-2346 [MEDIUM] CVE-2017-2346: An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Applic
An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Application Layer Gateway (ALG). Repeated crashes of the Service PC can result in an extended denial of service condition. The issue can be seen only if NAT or stateful-firewall rules are configured with ALGs enabled. This issue was caused by the code change for PR 1
nvd
CVE-2017-10610P4MEDIUMCVSS 5.9v12.1X46 prior to 12.1X46-D71v12.3X48 prior to 12.3X48-D55+1 more2017-10-13
CVE-2017-10610 [MEDIUM] CWE-20 CVE-2017-10610: On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause t
On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of the flowd process constitutes an extended denial of service condition for the SRX Series device. This issue only occurs if NAT64 is configured. Affected releases are Juniper Networks Junos OS 12.1X46 prior
nvd
CVE-2017-10611P4MEDIUMCVSS 5.9v14.1 prior to 14.1R8-S5, 14.1R9v14.2 prior to 14.2R7-S9, 14.2R8+9 more2017-10-13
CVE-2017-10611 [MEDIUM] CVE-2017-10611: If extended statistics are enabled via 'set chassis extended-statistics', when executing any operati
If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE processing can result in an extended denial of service condition. This issue only affects the foll
nvd
CVE-2020-1685P4MEDIUMCVSS 5.8≥ 18.1, < 18.1R3-S7≥ 18.2, < 18.2R2-S7, 18.2R3-S1+4 more2020-10-16
CVE-2020-1685 [MEDIUM] CWE-203 CVE-2020-1685: When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices u
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration similar to: family ethernet-switching { filter L2-VLAN { term ALLOW { from { user-vlan-id 100;
nvd
CVE-2017-10621P4MEDIUMCVSS 5.3v12.1X46 prior to 12.1X46-D71v12.3X48 prior to 12.3X48-D50+8 more2017-10-13
CVE-2017-10621 [MEDIUM] CWE-400 CVE-2017-10621: A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unau
A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9; 14.1X53 prior to 14.1X53-D50; 14.2 prior to 14.2R7-S9, 14.2R8; 15.1 prior
nvd
CVE-2020-1665P4MEDIUMCVSS 5.3≥ 17.2, < 17.2R3-S4≥ 17.2X75, < 17.2X75-D102, 17.2X75-D110+5 more2020-10-16
CVE-2020-1665 [MEDIUM] CWE-794 CVE-2020-1665: On Juniper Networks MX Series and EX9200 Series, in a certain condition the IPv6 Distributed Denial
On Juniper Networks MX Series and EX9200 Series, in a certain condition the IPv6 Distributed Denial of Service (DDoS) protection might not take affect when it reaches the threshold condition. The DDoS protection allows the device to continue to function while it is under DDoS attack, protecting both the Routing Engine (RE) and the Flexible PIC Concentr
nvd
CVE-2020-1628P4MEDIUMCVSS 5.3≥ 14.1X53, < 14.1X53-D53≥ 15.1, < 15.1R7-S6+13 more2020-04-08
CVE-2020-1628 [MEDIUM] CWE-200 CVE-2020-1628: Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration information such as heartbeats, kernel versions, etc. out to the Internet, leading to an information exposure vulnerability. This issue
nvd