Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 29 of 34
CVE-2021-0262P4MEDIUMCVSS 6.5≥ 19.1R3-S1, < 19.1*≥ 20.2, < 20.2R1-S22021-04-22
CVE-2021-0262 [MEDIUM] CWE-416 CVE-2021-0262: Through routine static code analysis of the Juniper Networks Junos OS software codebase, the Secure
Through routine static code analysis of the Juniper Networks Junos OS software codebase, the Secure Development Life Cycle team identified a Use After Free vulnerability in PFE packet processing on the QFX10002-60C switching platform. Exploitation of this vulnerability may allow a logically adjacent attacker to trigger a Denial of Service (DoS). Contin
nvd
CVE-2021-0242P4MEDIUMCVSS 6.5≥ 17.3, < 17.3R3-S11≥ 17.4, < 17.4R2-S13, 17.4R3-S4+11 more2021-04-22
CVE-2021-0242 [MEDIUM] CWE-119 CVE-2021-0242: A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switche
A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker sending specific unicast frames to trigger a Denial of Service (DoS) condition by exhausting DMA buffers, causing the FPC to crash and the device to restart. The DMA buffer leak is seen when receiving th
nvd
CVE-2021-0257P4MEDIUMCVSS 6.5≥ 17.3, < 17.3R3-S10≥ 17.4, < 17.4R3-S3+8 more2021-04-22
CVE-2021-0257 [MEDIUM] CWE-400 CVE-2021-0257: On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concent
On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IRB) interfaces are configured and mapped to a VPLS instance or a Bridge-Domain, certain Layer 2 network events at Customer Edge (CE) devices may cause memory leaks in the MPC of Provider Edge (PE) devices
nvd
CVE-2021-0228P4MEDIUMCVSS 6.5≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S11+12 more2021-04-22
CVE-2021-0228 [MEDIUM] CWE-754 CVE-2021-0228: An improper check for unusual or exceptional conditions vulnerability in Juniper Networks MX Series
An improper check for unusual or exceptional conditions vulnerability in Juniper Networks MX Series platforms with Trio-based MPC (Modular Port Concentrator) deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, may allow an attacker sending specific Layer 2 traffic to cause Distributed Denial of Service (DDoS) protection to tri
nvd
CVE-2021-0240P4MEDIUMCVSS 6.5≥ 17.3, < 17.3R3-S12≥ 17.4, < 17.4R3-S5+12 more2021-04-22
CVE-2021-0240 [MEDIUM] CWE-703 CVE-2021-0240: On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, the
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, the Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash if a malformed DHCPv6 packet is received, resulting in a restart of the daemon. The daemon automatically restarts without intervention, but continued receipt and pro
nvd
CVE-2021-31367P4MEDIUMCVSS 6.5≥ unspecified, < 18.4R3-S9≥ 19.1, < 19.1R3-S7+8 more2021-10-19
CVE-2021-31367 [MEDIUM] CWE-401 CVE-2021-31367: A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows an adjacent attacker to cause a Denial of Service (DoS) by sending genuine BGP flowspec packets which cause an FPC heap memory leak. Once having run out of memory the FPC will crash and restart al
nvd
CVE-2021-0288P4MEDIUMCVSS 6.5≥ 17.3, < 17.3R3-S12≥ 17.4, < 17.4R2-S13, 17.4R3-S5+12 more2021-07-15
CVE-2021-0288 [MEDIUM] CWE-754 CVE-2021-0288: A vulnerability in the processing of specific MPLS packets in Juniper Networks Junos OS on MX Series
A vulnerability in the processing of specific MPLS packets in Juniper Networks Junos OS on MX Series and EX9200 Series devices with Trio-based MPCs (Modular Port Concentrators) may cause FPC to crash and lead to a Denial of Service (DoS) condition. Continued receipt of this packet will sustain the Denial of Service (DoS) condition. This issue only aff
nvd
CVE-2021-0290P4MEDIUMCVSS 6.5≥ 16.1, < 16.1R7-S7≥ 17.1R1, < 17.1*+10 more2021-07-15
CVE-2021-0290 [MEDIUM] CWE-755 CVE-2021-0290: Improper Handling of Exceptional Conditions in Ethernet interface frame processing of Juniper Networ
Improper Handling of Exceptional Conditions in Ethernet interface frame processing of Juniper Networks Junos OS allows an attacker to send specially crafted frames over the local Ethernet segment, causing the interface to go into a down state, resulting in a Denial of Service (DoS) condition. The interface does not recover on its own and the FPC must
nvd
CVE-2021-0224P4MEDIUMCVSS 6.5≥ All, < 17.3R3-S12≥ 17.4, < 17.4R2-S13+11 more2021-04-22
CVE-2021-0224 [MEDIUM] CWE-770 CVE-2021-0224: A vulnerability in the handling of internal resources necessary to bring up a large number of Layer
A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes in Juniper Networks Junos OS can cause the Access Node Control Protocol daemon (ANCPD) to crash and restart, leading to a Denial of Service (DoS) condition. Continued processing of spoofed subscriber node
nvd
CVE-2021-0237P4MEDIUMCVSS 6.5≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S11+11 more2021-04-22
CVE-2021-0237 [MEDIUM] CVE-2021-0237: On Juniper Networks EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series deployed as a Virtu
On Juniper Networks EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series deployed as a Virtual Chassis with a specific Layer 2 circuit configuration, Packet Forwarding Engine manager (FXPC) process may crash and restart upon receipt of specific layer 2 frames. Continued receipt and processing of this packet will create a sustained Denial of Service (D
nvd
CVE-2021-0287P4MEDIUMCVSS 6.5≥ 19.4R1, < 19.4*≥ 20.1, < 20.1R2-S1, 20.1R3+2 more2021-07-15
CVE-2021-0287 [MEDIUM] CWE-754 CVE-2021-0287: In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evol
In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued link f
nvd
CVE-2022-22155P4MEDIUMCVSS 6.5≥ 18.4, < 18.4R3-S10≥ 19.1, < 19.1R3-S5+5 more2022-01-19
CVE-2022-22155 [MEDIUM] CWE-400 CVE-2022-22155: An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change eve
An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjacent attacker to cause a memory leak in the Flexible PIC Concentrator (FPC) of an ACX5448 router. The continuous flapping of an IPv6 neighbor with specific timing will cause the FPC to run out of resource
nvd
CVE-2022-22166P4MEDIUMCVSS 6.5≥ 20.4, < 20.4R3-S1≥ 21.1, < 21.1R2-S2, 21.1R32022-01-19
CVE-2022-22166 [MEDIUM] CWE-1284 CVE-2022-22166: An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (
An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause an rdp crash and thereby a Denial of Service (DoS). If a BGP update message is received over an established BGP session where a BGP SR-TE policy tunnel attribute
nvd
CVE-2023-36850P4MEDIUMCVSS 6.5≥ unspecified, < 19.1R3-S10≥ 19.2, < 19.2R3-S7+14 more2023-07-14
CVE-2023-36850 [MEDIUM] CWE-1285 CVE-2023-36850: An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connect
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Management(CFM) module of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an adjacent attacker on the local broadcast domain to cause a Denial of Service(DoS).
Upon receiving a malformed CFM packet, the MPC
nvd
CVE-2023-28970P4MEDIUMCVSS 6.5≥ unspecified, < 21.2R3-S4≥ 21.3, < 21.3R3-S4+5 more2023-04-17
CVE-2023-28970 [MEDIUM] CWE-703 CVE-2023-28970: An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the ne
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the device to cause a kernel crash, resulting in a Denial of Service (DoS). Continued receipt an
nvd
CVE-2024-39560P4MEDIUMCVSS 6.5fixed in 20.4R3-S9≥ 21.2R1, < 21.2*+6 more2024-07-10
CVE-2024-39560 [MEDIUM] CWE-755 CVE-2024-39560: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent downstream RSVP neighbor to cause kernel memory exhaustion, leading to a kernel crash, resulting in a Denial of Service (DoS).
The kernel memory leak and eventual crash will
nvd
CVE-2021-0295P4MEDIUMCVSS 6.1≥ 17.3, < 17.3R3-S12≥ 17.4, < 17.4R3-S5+12 more2021-07-15
CVE-2021-0295 [MEDIUM] CWE-697 CVE-2021-0295: A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos OS on the QFX10K Series switches allows an attacker to trigger a packet forwarding loop, leading to a partial Denial of Service (DoS). The issue is caused by DVMRP packets looping on a multi-homed Ethernet Segment Identifier (ESI) when VXLAN is configure
nvd
CVE-2016-4923P4MEDIUMCVSS 6.1v11.4 prior to 11.4R13-S3v12.1X44 prior to 12.1X44-D60+11 more2017-10-13
CVE-2016-4923 [MEDIUM] CWE-79 CVE-2016-4923: Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may pot
Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data and credentials from a J-Web session and to perform administrative actions on the Junos device. Juniper SIRT is not aware of any malicious exploitation of
nvd
CVE-2020-1607P4MEDIUMCVSS 6.1v17.2R2≥ 12.3, < 12.3R12-S15+18 more2020-01-15
CVE-2020-1607 [MEDIUM] CWE-79 CVE-2020-1607: Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker
Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12
nvd
CVE-2018-0008P4MEDIUMCVSS 6.2≥ 12.1X46, < 12.1X46-D71≥ 12.3X48, < 12.3X48-D55+9 more2018-01-10
CVE-2018-0008 [MEDIUM] CWE-287 CVE-2018-0008: An unauthenticated root login may allow upon reboot when a commit script is used. A commit script al
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts commit] stanza. Certain commit scripts that work without a problem during normal commit may cause unexpected behavior upon reboot wh
nvd