Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 3 of 34
CVE-2019-0002P3CRITICALCVSS 9.8≥ 15.1X53, < 15.1X53-D590≥ 18.1, < 18.1R3+1 more2019-01-15
CVE-2019-0002 [CRITICAL] CWE-794 CVE-2019-0002: On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer'
On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take effect. When this issue occurs, the output of the command: show pfe filter hw summary will not show the entry for: RACL group Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions
nvd
CVE-2019-0040P3CRITICALCVSS 9.1≥ 15.1, < 15.1F6-S12, 15.1R7-S4≥ 15.1X53, < 15.1X53-D236+6 more2019-04-10
CVE-2019-0040 [CRITICAL] CWE-200 CVE-2019-0040: On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). Ex
On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information leak vulnerability, responses were being generated from the source address of the management interface (e.g. fxp0) thus disclosing internal addressing and existence of the ma
nvd
CVE-2021-31350P3HIGHCVSS 8.8≥ 18.4, < 18.4R1-S8, 18.4R2-S8, 18.4R3-S8≥ 19.1, < 19.1R2-S3, 19.1R3-S5+7 more2021-10-19
CVE-2021-31350 [HIGH] CWE-269 CVE-2021-31350: An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension
An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to complete compromise of the targeted system. The issue is caused by the JET servic
nvd
CVE-2022-22246P3HIGHCVSS 8.8≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S6+11 more2022-10-18
CVE-2022-22246 [HIGH] CWE-829 CVE-2022-22246: A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS m
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabilities, and by circumventing existing attack requirements, successful exploitation could lead to a complete
nvd
CVE-2017-10601P3CRITICALCVSS 9.8v12.3 prior to 12.3R10, 12.3R11v12.3X48 prior to 12.3X48-D20+6 more2017-07-17
CVE-2017-10601 [CRITICAL] CWE-287 CVE-2017-10601: A specific device configuration can result in a commit failure condition. When this occurs, a user i
A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password while trying to login through console, ssh, ftp, telnet or su, etc., This issue relies upon a device configuration precondition to occur. Typically, device configurations are the result of a trusted
nvd
CVE-2022-22157P3CRITICALCVSS 9.3≥ 18.4, < 18.4R2-S9, 18.4R3-S9≥ 19.1, < 19.1R2-S3, 19.1R3-S6+8 more2022-01-19
CVE-2022-22157 [CRITICAL] CWE-863 CVE-2022-22157: A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gatew
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on the device. JDPI incorrectly classifies out-of-state asymmetric TCP flows as the dynamic
nvd
CVE-2020-1673P3HIGHCVSS 8.8≥ 18.1, < 18.1R3-S11≥ 18.2, < 18.2R3-S5+7 more2020-10-16
CVE-2020-1673 [HIGH] CWE-79 CVE-2020-1673: Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTT
Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTTPS) services allows an unauthenticated attacker to hijack the target user's HTTP/HTTPS session and perform administrative actions on the Junos device as the targeted user. This issue only affects Juniper Networks Junos OS devices with HTTP/HTTPS services e
nvd
CVE-2021-31382P3CRITICALCVSS 9.0≥ 17.2R1, < 17.2*≥ 17.3, < 17.3R3-S12+23 more2021-10-19
CVE-2021-31382 [CRITICAL] CWE-362 CVE-2021-31382: On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vul
On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the device's interfaces with incorrect firewall filters. This issue only occurs when upgrading the device to an affected version of
nvd
CVE-2018-0016P3HIGHCVSS 7.5≥ 15.1, < 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5≥ 15.1X49, < 15.1X49-D60+1 more2018-04-11
CVE-2018-0016 [HIGH] CVE-2018-0016: Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interf
Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'clns-routing' or ES-IS is explicitly configured. Devices with without CLNS enabled are not vulnerable to
nvd
CVE-2026-33785P3HIGHCVSS 8.8≥ 24.4, < 24.4R2-S3≥ 25.2, < 25.2R22026-04-09
CVE-2026-33785 [HIGH] CWE-862 CVE-2026-33785: A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices.
Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These c
nvd
CVE-2020-1656P3HIGHCVSS 8.8≥ 12.3, < 12.3R12-S15≥ 12.3X48, < 12.3X48-D95+19 more2020-10-16
CVE-2020-1656 [HIGH] CWE-20 CVE-2020-1656: The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Netw
The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vulnerability which will result in a Denial of Service (DoS) condition when a DHCPv6 client sends a specific DHPCv6 message allowing an attacker to potentially perform a Remote Code Execution (RCE) attack on t
nvd
CVE-2020-1606P3HIGHCVSS 8.1≥ 12.3, < 12.3R12-S13≥ 14.1X53, < 14.1X53-D51+17 more2020-01-15
CVE-2020-1606 [HIGH] CWE-22 CVE-2020-1606: A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-
A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by root user. This issue affects Juniper Networks Junos OS: 12.3 versions prior to
nvd
CVE-2025-52983P3HIGHCVSS 7.2fixed in 22.2R3-S7≥ 22.4, < 22.4R3-S5+3 more2025-07-11
CVE-2025-52983 [HIGH] CWE-446 CVE-2025-52983: A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Ho
A UI Discrepancy for Security Feature
vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device.
On VM Host Routing Engines (RE), even if the configured public key for root has been removed, remote users which are in possession of the corresponding private key can st
nvd
CVE-2021-0268P3CRITICALCVSS 9.3≥ 18.1, < 18.1R3-S11≥ 18.2, < 18.2R3-S5+7 more2021-04-22
CVE-2021-0268 [CRITICAL] CWE-79 CVE-2021-0268: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication. The weakness can be exp
nvd
CVE-2018-0043P3HIGHCVSS 8.8≥ 12.1X46, < 12.1X46-D77≥ 12.3X48, < 12.3X48-D75+18 more2018-10-10
CVE-2018-0043 [HIGH] CWE-20 CVE-2018-0043: Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and r
Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending specific MPLS packets, an attacker can repeatedly crash the RPD process causing a sustained Denial of Service. This issue affects both IPv4 and IPv6. This issue can only be exploited from
nvd
CVE-2021-31354P3HIGHCVSS 8.8≥ 19.2, < 19.2R3-S3≥ 19.3, < 19.3R3-S3+5 more2021-10-19
CVE-2021-31354 [HIGH] CWE-125 CVE-2021-31354: An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License
An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause a partial Denial of Service (DoS), or lead to remote code execution (RCE). The vulnerability
nvd
CVE-2018-0044P3HIGHCVSS 8.1≥ 18.1, < 18.1R42018-10-10
CVE-2018-0044 [HIGH] CWE-287 CVE-2018-0044: An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series dev
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4
nvd
CVE-2026-21906P3HIGHCVSS 7.5fixed in 21.4R3-S12≥ 22.4, < 22.4R3-S8+5 more2026-01-15
CVE-2026-21906 [HIGH] CWE-755 CVE-2026-21906: An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) o
An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart.
When PowerMode IPsec (PMI) and GRE performance acceleration are enable
nvd
CVE-2018-0057P3CRITICALCVSS 9.6≥ 15.1, < 15.1R7-S2, 15.1R8≥ 16.1, < 16.1R4-S12, 16.1R7-S2, 16.1R8+6 more2018-10-10
CVE-2018-0057 [CRITICAL] CVE-2018-0057: On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers l
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address binding in the access profile. In the problem scenario, with a hardware-address and IP address configured und
nvd
CVE-2026-57026P3HIGHCVSS 7.5fixed in 23.2R2-S7≥ 23.4, < 23.4R2-S8+4 more2026-07-09
CVE-2026-57026 [HIGH] CWE-1286 CVE-2026-57026: An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a fl
nvd