cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 34 of 34
CVE-2018-0056P4MEDIUMCVSS 5.3≥ 15.1, < 15.1R7-S1≥ 16.1, < 16.1R4-S12, 16.1R6-S6+6 more2018-10-10
CVE-2018-0056 [MEDIUM] CWE-20 CVE-2018-0056: If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC ad If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to delete the duplicate MAC address when the particular entry is not found in the internal MAC address
nvd
CVE-2024-21610P4MEDIUMCVSS 4.3fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S7+7 more2024-04-12
CVE-2024-21610 [MEDIUM] CWE-755 CVE-2024-21610: An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) o An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). In a scaled CoS scenario with 1000s of interfaces, when specific low privileged commands, received over NETCON
nvd
CVE-2023-36836P4MEDIUMCVSS 4.7≥ 19.4R3-S4, < 19.4*≥ 20.1R2, < 20.1*+9 more2023-07-14
CVE-2023-36836 [MEDIUM] CWE-908 CVE-2023-36836: A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Net A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, in a Multicast only Fast Reroute (MoFRR) scenario, the rpd process can
nvd
CVE-2021-0243P4MEDIUMCVSS 4.7≥ unspecified, < 17.3R3-S10≥ 17.4, < 17.4R3-S3+10 more2021-04-22
CVE-2021-0243 [MEDIUM] CWE-241 CVE-2021-0243: Improper Handling of Unexpected Data in the firewall policer of Juniper Networks Junos OS on EX4300 Improper Handling of Unexpected Data in the firewall policer of Juniper Networks Junos OS on EX4300 switches allows matching traffic to exceed set policer limits, possibly leading to a limited Denial of Service (DoS) condition. When the firewall policer discard action fails on a Layer 2 port, it will allow traffic to pass even though it exceeds set pol
nvd
CVE-2026-21912P4MEDIUMCVSS 4.7fixed in 21.2R3-S10≥ 21.4, < 21.4R3-S9+5 more2026-01-15
CVE-2026-21912 [MEDIUM] CWE-367 CVE-2026-21912: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ether A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. On MX10k Series systems with LC480 or LC2101
nvd
CVE-2023-28975P4MEDIUMCVSS 4.6≥ unspecified, < 19.4R3-S10≥ 20.2, < 20.2R3-S7+10 more2023-04-17
CVE-2023-28975 [MEDIUM] CWE-394 CVE-2023-28975: An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS a An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a Denial of Service (DoS). When certain USB devices are connected to a USB port of the routing-engine (RE), the kernel will crash leading to a reboot of the device. The devi
nvd
CVE-2026-21901P4MEDIUMCVSS 4.4≥ 22.3, < 22.3R3-S5≥ 22.4, < 22.4R3-S10+2 more2026-07-09
CVE-2026-21901 [MEDIUM] CWE-476 CVE-2026-21901: A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS). A local high-privileged user configuring or deactivating a specific 'system services ss
nvd
CVE-2017-10606P4MEDIUMCVSS 4.4v15.1X49 prior to TPM firmware version 4.432017-10-13
CVE-2017-10606 [MEDIUM] CVE-2017-10606: Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a w Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX300 Series to encrypt sensitive configuration data. While other products also ship with a TPM, no other p
nvd
CVE-2023-22405MEDIUMCVSS 6.5≥ unspecified, < 20.2R3-S5≥ 20.3, < 20.3R3-S5+6 more2023-01-12
CVE-2023-22405 [MEDIUM] CWE-1250 Junos OS: QFX5k Series, EX46xx Series: MAC limiting feature stops working after PFE restart or device reboot Junos OS: QFX5k Series, EX46xx Series: MAC limiting feature stops working after PFE restart or device reboot An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (
cvelistv5
CVE-2022-22234MEDIUMCVSS 5.5≥ unspecified, < 18.4R3-S11≥ 19.1, < 19.1R3-S9+11 more2022-10-18
CVE-2022-22234 [MEDIUM] CWE-1250 Junos OS: EX2300 and EX3400 Series: One of more SFPs might become unavailable when the system is very busy Junos OS: EX2300 and EX3400 Series: One of more SFPs might become unavailable when the system is very busy An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to cause a Denial o
cvelistv5