cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 5 of 34
CVE-2026-21917P3HIGHCVSS 7.5≥ 23.2R2-S2, < 23.2R2-S5≥ 23.4R2-S1, < 23.4R2-S5+2 more2026-01-15
CVE-2026-21917 [HIGH] CWE-1286 CVE-2026-21917: An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module o An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC cras
nvd
CVE-2026-21905P3HIGHCVSS 7.5fixed in 21.2R3-S10≥ 21.4, < 21.4R3-S12+6 more2026-01-15
CVE-2026-21905 [HIGH] CWE-835 CVE-2026-21905: A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (Do
nvd
CVE-2024-21597P3HIGHCVSS 7.5fixed in 20.4R3-S9≥ 21.2, < 21.2R3-S3+4 more2024-01-12
CVE-2024-21597 [HIGH] CWE-668 CVE-2024-21597: An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juni An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if routing-instances (RI) are configured, specific valid traffic destined to the device
nvd
CVE-2019-0062P3HIGHCVSS 8.8≥ 12.3, < 12.3R12-S15≥ 12.3X48, < 12.3X48-D85+15 more2019-10-09
CVE-2019-0062 [HIGH] CWE-384 CVE-2019-0062: A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineerin A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15 on EX Series; 12.3X48 versions prior to 12.3X48-D8
nvd
CVE-2020-1603P3HIGHCVSS 8.6≥ 16.1, < 16.1R7-S6≥ 16.2, < 16.2R2-S11+11 more2020-01-15
CVE-2020-1603 [HIGH] CWE-710 CVE-2020-1603: Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. T Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which point a mbuf memory leak occurs within the Juniper Networks Junos OS device. This memory leak event
nvd
CVE-2021-0269P3HIGHCVSS 8.8≥ unspecified, < 17.4R3-S3≥ 18.1, < 18.1R3-S12+9 more2021-04-22
CVE-2021-0269 [HIGH] CWE-233 CVE-2021-0269: The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an atta The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device when a user is authenticated to J-Web. An attacker may be able to supersede existing parameters, including hardcoded parameters within the HTTP/S session, access and exploit v
nvd
CVE-2021-0251P3HIGHCVSS 8.6≥ 17.3R1, < 17.3*≥ 17.4, < 17.4R2-S9, 17.4R3-S2+7 more2021-04-22
CVE-2021-0251 [HIGH] CWE-476 CVE-2021-0251: A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daem A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC allows an attacker to send malformed HTTP packets to the device thereby causing a Denial of Service (DoS), crashing the Multiservices PIC Management Daemon (mspmand
nvd
CVE-2024-39547P3HIGHCVSS 7.5fixed in 21.2R3-S8≥ 21.4, < 21.4R3-S7+6 more2024-10-11
CVE-2024-39547 [HIGH] CWE-755 CVE-2024-39547: An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks J An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU-based Denial of Service (DoS). If specially crafted TCP traffic is received by the control p
nvd
CVE-2026-33793P3HIGHCVSS 7.8fixed in 22.4R3-S7≥ 23.2, < 23.2R2-S4+3 more2026-04-09
CVE-2026-33793 [HIGH] CWE-250 CVE-2026-33793: An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Network An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute mali
nvd
CVE-2024-39540P3HIGHCVSS 7.5≥ 21.2R3-S5, < 21.2R3-S62024-07-11
CVE-2024-39540 [HIGH] CWE-754 CVE-2024-39540: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives specific valid TCP traffic, the pfe crashes and restarts
nvd
CVE-2026-33790P3HIGHCVSS 7.5fixed in 21.2R3-S10≥ 21.4, < 21.4R3-S12+10 more2026-04-09
CVE-2026-33790 [HIGH] CWE-754 CVE-2026-33790: An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustai
nvd
CVE-2025-30658P3HIGHCVSS 7.5fixed in 21.2R3-S9≥ 21.4, < 21.4R3-S10+5 more2025-04-09
CVE-2025-30658 [HIGH] CWE-401 CVE-2025-30658: A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of J A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX platforms with Anti-Virus enabled, if a server sends specific content in the HTTP body of a response to a client re
nvd
CVE-2025-30649P3HIGHCVSS 7.5fixed in 22.2R3-S6≥ 22.4, < 22.4R3-S4+3 more2025-04-09
CVE-2025-30649 [HIGH] CWE-20 CVE-2025-30649: An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Ju An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-SPC3 Security Services Card allows an unauthenticated, network-based attacker, to send specific spoofed packets to cause a CPU Denial of Service (DoS) to the MX-SPC3 SPUs. Continued receipt and processing
nvd
CVE-2026-21913P3HIGHCVSS 7.5≥ 24.4, < 24.4R2≥ 25.2, < 25.2R1-S2, 25.2R22026-01-15
CVE-2026-21913 [HIGH] CWE-665 CVE-2026-21913: An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Junipe An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause a
nvd
CVE-2023-44198P3HIGHCVSS 7.5≥ 20.4, < 20.4R3-S5≥ 21.1, < 21.1R3-S4+7 more2023-10-13
CVE-2023-44198 [HIGH] CWE-754 CVE-2023-44198: An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Net An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks. If the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents th
nvd
CVE-2022-22156P3HIGHCVSS 7.4≥ unspecified, < 18.4R2-S9, 18.4R3-S9≥ 19.1, < 19.1R2-S3, 19.1R3-S7+8 more2022-01-19
CVE-2022-22156 [HIGH] CWE-295 CVE-2022-22156: An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to p An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of the device. The following command can be executed by an administrator via
nvd
CVE-2018-0021P3HIGHCVSS 8.8≥ 14.1, < 14.1R10, 14.1R9≥ 14.1X53, < 14.1X53-D47+6 more2018-04-11
CVE-2018-0021 [HIGH] CVE-2018-0021: If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CAK) key are not configured, all remaining digits will be auto-configured to 0. Hence, Juniper devices configured with short MacSec keys are at risk to an increased likelihood that an attacker will discover the secret passphrases configured for
nvd
CVE-2021-0203P3HIGHCVSS 8.6≥ 15.1, < 15.1R7-S7≥ 16.1, < 16.1R7-S8+12 more2021-01-15
CVE-2021-0203 [HIGH] CWE-794 CVE-2021-0203: On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop broadcast, multicast, and unknown unicast packets when a specified traffic
nvd
CVE-2019-0070P3HIGHCVSS 8.8≥ unspecified, < 18.2R12019-10-09
CVE-2019-0070 [HIGH] CWE-20 CVE-2019-0070: An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This leads to the attacker being able to take control of the entire system. This issue affects: Junipe
nvd
CVE-2019-0041P3HIGHCVSS 8.6≥ 18.2, < 18.2R1-S2, 18.2R22019-04-10
CVE-2019-0041 [HIGH] CWE-284 CVE-2019-0041: On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the cont On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 versions prior to 18.2R1-S2, 18.2R2 on EX4300-MP Series. This issue does not affect any other EX series devices.
nvd
Juniper Networks Junos Os vulnerabilities | cvebase