cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 31 of 34
CVE-2021-0256P4MEDIUMCVSS 5.5≥ 17.3, < 17.3R3-S12≥ 17.4, < 17.4R3-S4+7 more2021-04-22
CVE-2021-0256 [MEDIUM] CWE-250 CVE-2021-0256: A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability to read portions of sensitive files, such as the master.passwd file. Since mosquitto is shipped with setuid permissions enabled and is owned by the root user, this vulnerabil
nvd
CVE-2025-21592P4MEDIUMCVSS 5.5fixed in 21.4R3-S8≥ 22.2, < 22.2R3-S5+4 more2025-01-09
CVE-2025-21592 [MEDIUM] CWE-200 CVE-2025-21592: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line inte An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the file system. Through the execution of either 'show services advanced-anti-m
nvd
CVE-2025-30654P4MEDIUMCVSS 5.5fixed in 21.4R3-S10≥ 22.2, < 22.2R3-S5+3 more2025-04-09
CVE-2025-30654 [MEDIUM] CWE-200 CVE-2025-30654: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (U An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Through the execution of a specific show mgd command, a user with limited permissions
nvd
CVE-2024-39511P4MEDIUMCVSS 5.5fixed in 20.4R3-S10≥ 21.2, < 21.2R3-S7+6 more2024-07-10
CVE-2024-39511 [MEDIUM] CWE-20 CVE-2024-39511: An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Ne An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x daemon crashes. An attacker can cause a sustained DoS condition by running th
nvd
CVE-2018-0063P4MEDIUMCVSS 6.5≥ 17.3R3, < 17.3R3-S12018-10-10
CVE-2018-0063 [MEDIUM] CWE-400 CVE-2018-0063: A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP reques A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing interfaces (IRIs) next-hop limit. Once the IRI next-hop database is full, no further next hops can be learned and existing entries cannot be cleared, leading to a sustained de
nvd
CVE-2023-36840P4MEDIUMCVSS 5.5≥ unspecified, < 19.3R3-S10≥ 20.1, < 20.1R3-S4+10 more2023-07-14
CVE-2023-36840 [MEDIUM] CWE-617 CVE-2023-36840: A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS an A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved, when a specific L2VPN command is run, RPD will crash and restart. Continued execution of this specific comman
nvd
CVE-2024-30384P4MEDIUMCVSS 5.5fixed in 20.4R3-S10≥ 21.2, < 21.2R3-S7+1 more2024-04-12
CVE-2024-30384 [MEDIUM] CWE-754 CVE-2024-30384: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows a locally authenticated attacker with low privileges to cause a Denial-of-Service (Dos). If a specific CLI command is issued, a PFE crash will occur. This will cause traffic forwarding to b
nvd
CVE-2023-44177P4MEDIUMCVSS 5.5fixed in 19.1R3-S10≥ 19.2, < 19.2R3-S7+11 more2023-10-13
CVE-2023-44177 [MEDIUM] CWE-121 CVE-2023-44177: A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS: * All ve
nvd
CVE-2023-44176P4MEDIUMCVSS 5.5fixed in 20.4R3-S8≥ 21.2, < 21.2R3-S6+4 more2023-10-13
CVE-2023-44176 [MEDIUM] CWE-121 CVE-2023-44176: A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS: * All versions prio
nvd
CVE-2023-44178P4MEDIUMCVSS 5.5fixed in 19.1R3-S10≥ 19.2, < 19.2R3-S7+12 more2023-10-13
CVE-2023-44178 [MEDIUM] CWE-121 CVE-2023-44178: A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS * All versions prior
nvd
CVE-2026-57025P4MEDIUMCVSS 5.5fixed in 23.2R2-S7≥ 23.4, < 23.4R2-S7+2 more2026-07-09
CVE-2026-57025 [MEDIUM] CWE-466 CVE-2026-57025: A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper N A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' comma
nvd
CVE-2026-33786P4MEDIUMCVSS 5.5≥ 24.4, < 24.4R1-S3, 24.4R22026-04-09
CVE-2026-33786 [MEDIUM] CWE-754 CVE-2026-33786: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts whic
nvd
CVE-2026-33802P4MEDIUMCVSS 5.5≥ 23.2R2, < 23.2R2-S6≥ 23.4, < 23.4R2-S8+4 more2026-07-09
CVE-2026-33802 [MEDIUM] CWE-862 CVE-2026-33802: A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI '
nvd
CVE-2023-44183P4MEDIUMCVSS 5.3≥ 18.4R2, < 18.4*≥ 20.4, < 20.4R3-S8+8 more2023-10-13
CVE-2023-44183 [MEDIUM] CWE-20 CVE-2023-44183: An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper N An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series devices allows an unauthenticated, adjacent attacker, sending two or more genuine packets in the same VxLAN topology to possibly cause a DMA memory leak to occur under various specific operational conditi
nvd
CVE-2024-30386P4MEDIUMCVSS 5.3fixed in 20.4R3-S8≥ 21.2, < 21.2R3-S6+6 more2024-04-12
CVE-2024-30386 [MEDIUM] CWE-416 CVE-2024-30386: A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause l2ald to crash leading to a Denial-of-Service (DoS). In an EVPN-VXLAN scenario, when state updates are received and processed by the affected system, the correct order o
nvd
CVE-2025-59962P4MEDIUMCVSS 5.3≥ 21.4, < 21.4R3-S6≥ 22.1, < 22.1R3-S6+4 more2025-10-09
CVE-2025-59962 [MEDIUM] CWE-824 CVE-2025-59962: An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Net An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a Denial of Service (DoS). With
nvd
CVE-2025-52989P4MEDIUMCVSS 5.1fixed in 22.2R3-S7≥ 22.4, < 22.4R3-S7+4 more2025-07-11
CVE-2025-52989 [MEDIUM] CWE-140 CVE-2025-52989: An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Ju An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part
nvd
CVE-2022-22215P4MEDIUMCVSS 5.5≥ unspecified, < 19.1R3-S8≥ 19.2, < 19.2R3-S6+8 more2022-07-20
CVE-2022-22215 [MEDIUM] CWE-772 CVE-2022-22215: A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable au A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). It is possible that after the termination of a gRPC connection the respective/v
nvd
CVE-2017-10613P4MEDIUMCVSS 5.5v12.1X46 prior to 12.1X46-D55v12.3X48 prior to 12.3X48-D35+7 more2017-10-13
CVE-2017-10613 [MEDIUM] CWE-400 CVE-2017-10613: A vulnerability in a specific loopback filter action command, processed in a specific logical order A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a running configuration of Juniper Networks Junos OS, allows an attacker with CLI access and the ability to initiate remote sessions to the loopback interface with the defined action, to hang the kernel. Affected releases are Juniper N
nvd
CVE-2022-22193P4MEDIUMCVSS 5.5≥ 20.3, < 20.3R3-S1≥ 20.4, < 20.4R3+2 more2022-04-14
CVE-2022-22193 [MEDIUM] CWE-241 CVE-2022-22193: An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of J An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Continued execution of this command might cause a sustained Denial of Service condition. If BGP rib sharding
nvd