Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 33 of 34
CVE-2020-1682P4MEDIUMCVSS 5.5≥ 15.1X49, < 15.1X49-D220≥ 17.4, < 17.4R3-S3+6 more2020-10-16
CVE-2020-1682 [MEDIUM] CWE-20 CVE-2020-1682: An input validation vulnerability exists in Juniper Networks Junos OS, allowing an attacker to crash
An input validation vulnerability exists in Juniper Networks Junos OS, allowing an attacker to crash the srxpfe process, causing a Denial of Service (DoS) through the use of specific maintenance commands. The srxpfe process restarts automatically, but continuous execution of the commands could lead to an extended Denial of Service condition. This issue
nvd
CVE-2016-4924P4MEDIUMCVSS 5.5v15.1 prior to 15.1F5v14.1 prior to 14.1R82017-10-13
CVE-2016-4924 [MEDIUM] CWE-275 CVE-2016-4924: An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivile
An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host system read access to vMX or vPFE images and obtain sensitive information contained in them such as private cryptographic keys. This issue was found during internal product security testing. Juniper SIRT is not aware of any malicious
nvd
CVE-2021-0293P4MEDIUMCVSS 5.5≥ 18.3, < 18.3R3-S4≥ 18.4, < 18.4R1-S8, 18.4R2-S6, 18.4R3-S7+8 more2021-07-15
CVE-2021-0293 [MEDIUM] CWE-401 CVE-2021-0293: A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lif
A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI command 'show system connections extensive' is executed. The amount of memory leaked on each execution depends on the number of TCP connections from and to the system. Repeated execution will cause more mem
nvd
CVE-2024-47496P4MEDIUMCVSS 5.5fixed in 21.4R3-S9≥ 22.2, < 22.2R3-S5+4 more2024-10-11
CVE-2024-47496 [MEDIUM] CWE-476 CVE-2024-47496: A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks J
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS).
When a specific command is executed, the pfe crashes. This will cause traffic forwarding to be interrupted until the system self-recovers. Repeated execution will cre
nvd
CVE-2021-31377P4MEDIUMCVSS 5.5≥ 15.1, < 15.1R7-S9≥ 17.3, < 17.3R3-S12+13 more2021-10-19
CVE-2021-31377 [MEDIUM] CWE-732 CVE-2021-31377: An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the file
An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This is
nvd
CVE-2024-30378P4MEDIUMCVSS 5.5fixed in 20.4R3-S5≥ 21.1, < 21.1R3-S4+6 more2024-04-16
CVE-2024-30378 [MEDIUM] CWE-416 CVE-2024-30378: A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allow
A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition. The process crashes and restarts automatically.
When speci
nvd
CVE-2023-22409P4MEDIUMCVSS 5.5≥ unspecified, < 19.4R3-S10≥ 20.1R1, < 20.1*+9 more2023-01-13
CVE-2023-22409 [MEDIUM] CWE-1284 CVE-2023-22409: An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS al
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS). When an inconsistent "deterministic NAT" configuration is present on an SRX, or MX with SPC3 and then a specific CLI command is issued the SPC will crash and
nvd
CVE-2023-44193P4MEDIUMCVSS 5.5fixed in 20.4R3-S7≥ 21.1, < 21.1R3-S5+6 more2023-10-13
CVE-2023-44193 [MEDIUM] CWE-401 CVE-2023-44193: An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Eng
An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS).
On all Junos MX Series with MPC1 - MPC9, LC480, LC2101, MX10003, and MX80, when Connectivity-Fault-Management (CFM
nvd
CVE-2025-21596P4MEDIUMCVSS 5.5fixed in 21.4R3-S9≥ 22.2, < 22.2R3-S5+4 more2025-01-09
CVE-2025-21596 [MEDIUM] CWE-755 CVE-2025-21596: An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Junip
An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' command to cause the chassis daemon (chassisd) to crash and restart, resulting in a tempor
nvd
CVE-2018-0055P4MEDIUMCVSS 5.3≥ 15.1, < 15.1R7-S2≥ 15.1X49, < 15.1X49-D160+10 more2018-10-10
CVE-2018-0055 [MEDIUM] CWE-20 CVE-2018-0055: Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP ser
Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband Edge (BBE) environment may result in a jdhcpd daemon crash. The daemon automatically restarts without intervention, but a continuous receipt of crafted DHCPv6 packets could leaded to an extended denial of service condition. This issue
nvd
CVE-2021-0289P4MEDIUMCVSS 5.3≥ 5.6R1, < 5.6*≥ 15.1, < 15.1R7-S10+16 more2021-07-15
CVE-2021-0289 [MEDIUM] CWE-367 CVE-2021-0289: When user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) inte
When user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) interface units, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability between the Device Control Daemon (DCD) and firewall process (dfwd) daemons of Juniper Networks Junos OS allows an attacker to bypass the user-defined ARP Policer. In this pa
nvd
CVE-2023-28984P4MEDIUMCVSS 5.3≥ unspecified, < 19.4R3-S10≥ 20.2, < 20.2R3-S7+8 more2023-04-17
CVE-2023-28984 [MEDIUM] CWE-362 CVE-2023-28984: A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks J
A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of MAC learning and aging happens, but due to a Race Condition (Concurrent
nvd
CVE-2024-21615P4MEDIUMCVSS 5.0fixed in 21.2R3-S7≥ 21.4, < 21.4R3-S5+5 more2024-04-12
CVE-2024-21615 [MEDIUM] CWE-276 CVE-2024-21615: An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved all
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system.
On all Junos OS and Junos OS Evolved platforms, when NETCONF traceoptions are configured, and a super-user performs specific actions via NETCONF, then a low-privil
nvd
CVE-2023-28979P4MEDIUMCVSS 4.7≥ unspecified, < 19.3R3-S7≥ 19.4, < 19.4R3-S9+9 more2023-04-17
CVE-2023-28979 [MEDIUM] CWE-754 CVE-2023-28979: An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Netwo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity check. In a 6PE scenario and if an additional integrity check is configured, it will fail to drop specific malformed IPv6 packets, and then these packets will be forwarded
nvd
CVE-2026-57031P4MEDIUMCVSS 4.7≥ 23.2R2-S1, < 23.2R2-S7≥ 23.4R2, < 23.4R2-S7+3 more2026-07-09
CVE-2026-57031 [MEDIUM] CWE-754 CVE-2026-57031: An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engin
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters.
On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters
nvd
CVE-2022-22243P4MEDIUMCVSS 4.3≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R3-S6+11 more2022-10-18
CVE-2022-22243 [MEDIUM] CWE-20 CVE-2022-22243: An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue affects Juniper Networks Junos OS: al
nvd
CVE-2019-0009P4MEDIUMCVSS 5.5≥ 15.1X53, < 15.1X53-D113, 15.1X53-D590≥ 18.1, < 18.1R2-S2, 18.1R3+1 more2019-01-15
CVE-2019-0009 [MEDIUM] CVE-2019-0009: On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the rout
On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine (PFE). In a virtual chassis (VC) deployment, this issue disrupts communication between the VC members. This issue does not affect other Junos platforms. Affected releases are Junos OS on EX2300 and EX3400 series:
nvd
CVE-2021-0238P4MEDIUMCVSS 5.5≥ 17.3R1, < 17.3*≥ 17.4, < 17.4R3-S5+12 more2021-04-22
CVE-2021-0238 [MEDIUM] CWE-400 CVE-2021-0238: When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Proto
When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cause the system to run out of disk space, excessive disk usage may cause other complications. An administrator can use the following CLI command to monitor the available disk space: user@device> show system
nvd
CVE-2024-47501P4MEDIUMCVSS 5.5fixed in 21.2R3-S1≥ 21.3, < 21.3R3+1 more2024-10-11
CVE-2024-47501 [MEDIUM] CWE-476 CVE-2024-47501: A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks
A NULL Pointer Dereference vulnerability in the
packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS).
In a VPLS or Junos Fusion scenario, the execution of specific show commands will caus
nvd
CVE-2018-0006P4MEDIUMCVSS 5.3≥ 15.1, < 15.1R6-S2, 15.1R7≥ 16.1, < 16.1R5-S1, 16.1R6+3 more2018-01-10
CVE-2018-0006 [MEDIUM] CWE-770 CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain
A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to exc
nvd