Juniper Networks Junos Os vulnerabilities
670 known vulnerabilities affecting juniper_networks/junos_os.
Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338
Vulnerabilities
Page 7 of 34
CVE-2021-0260P3HIGHCVSS 7.3≥ 17.2R1, < 17.2*≥ 17.3, < 17.3R3-S9+8 more2021-04-22
CVE-2021-0260 [HIGH] CWE-285 CVE-2021-0260: An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) ser
An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Control Sphere, or write actions to OIDs that support write operations, against the device without a
nvd
CVE-2018-0005P3HIGHCVSS 8.8≥ 14.1X53, < 14.1X53-D40≥ 15.1X53, < 15.1X53-D55+1 more2018-01-10
CVE-2018-0005 [HIGH] CWE-754 CVE-2018-0005: QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forwa
QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or other unintended conditions. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D40; 15.1X53 versions prior to 15.1X53-D55; 15.1 versions prior
nvd
CVE-2020-1632P3HIGHCVSS 8.6≥ 16.1, < 16.1R7-S6≥ 16.2, < 16.2R2-S11+12 more2020-04-15
CVE-2020-1632 [HIGH] CWE-755 CVE-2020-1632: In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos
In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of Service (DoS) condition. For example, Router A sends a specific BGP UPDATE to
nvd
CVE-2018-0048P3HIGHCVSS 7.5≥ 17.2, < 17.2R1-S7, 17.2R2-S6, 17.2R3≥ 17.2X75, < 17.2X75-D102, 17.2X75-D110+3 more2018-10-10
CVE-2018-0048 [HIGH] CWE-400 CVE-2018-0048: A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support c
A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhaustion condition on the device. This can have an adverse impact on the system performance and availability. This issue only affects devices with JET support running Junos OS 17
nvd
CVE-2019-0039P3HIGHCVSS 8.1≥ 14.1X53, < 14.1X53-D49≥ 15.1, < 15.1F6-S12, 15.1R7-S3+13 more2019-04-10
CVE-2019-0039 [HIGH] CWE-307 CVE-2019-0039: If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The hi
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionally, administrators who do not enforce a strong password policy can increase the likelihood of success from brute forc
nvd
CVE-2020-1667P3HIGHCVSS 8.3≥ 17.3, < 17.3R3-S8≥ 18.3, < 18.3R3-S1+4 more2020-10-16
CVE-2020-1667 [HIGH] CWE-362 CVE-2020-1667: When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS
When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process might be bypassed due to a race condition. Due to this vulnerability, mspmand process, responsible for managing "URL Filtering ser
nvd
CVE-2020-1645P3HIGHCVSS 8.3≥ 17.3, < 17.3R3-S8≥ 18.3, < 18.3R2-S4, 18.3R3-S1+5 more2020-07-17
CVE-2020-1645 [HIGH] CWE-362 CVE-2020-1645: When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS
When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filtering service", may crash, causing the Services PIC to restart. While the Services PIC is resta
nvd
CVE-2021-0218P3HIGHCVSS 7.8≥ 17.3, < 17.3R3-S9≥ 17.4, < 17.4R2-S12, 17.4R3-S3+10 more2021-01-15
CVE-2021-0218 [HIGH] CWE-78 CVE-2021-0218: A command injection vulnerability in the license-check daemon of Juniper Networks Junos OS that may
A command injection vulnerability in the license-check daemon of Juniper Networks Junos OS that may allow a locally authenticated attacker with low privileges to execute commands with root privilege. license-check is a daemon used to manage licenses in Junos OS. To update licenses, a user executes the command 'request system license update' via the CLI. A
nvd
CVE-2021-0223P3HIGHCVSS 7.8≥ unspecified, < 15.1R7-S9≥ 17.3, < 17.3R3-S11+11 more2021-01-15
CVE-2021-0223 [HIGH] CWE-250 CVE-2021-0223: A local privilege escalation vulnerability in telnetd.real of Juniper Networks Junos OS may allow a
A local privilege escalation vulnerability in telnetd.real of Juniper Networks Junos OS may allow a locally authenticated shell user to escalate privileges and execute arbitrary commands as root. telnetd.real is shipped with setuid permissions enabled and is owned by the root user, allowing local users to run telnetd.real with root privileges. This issue
nvd
CVE-2021-0261P3HIGHCVSS 7.5≥ 12.3, < 12.3R12-S17≥ 12.3X48, < 12.3X48-D105+14 more2021-04-22
CVE-2021-0261 [HIGH] CWE-125 CVE-2021-0261: A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Fir
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for these services by sending a high number of specific requests. This issue affects: Juniper Networks
nvd
CVE-2022-22185P3HIGHCVSS 7.5≥ unspecified, < 18.3R3-S6≥ 17.3R1, < 17.3*+11 more2022-04-14
CVE-2022-22185 [HIGH] CWE-754 CVE-2022-22185: A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated a
A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a Denial of Service (DoS) by sending a specific fragmented packet to the device, resulting in a flowd process crash, which is responsible for packet forwarding. Continued receipt and processing of this specific packet will create a sust
nvd
CVE-2022-22223P3HIGHCVSS 7.5≥ unspecified, < 15.1R7-S11≥ 18.4, < 18.4R2-S10, 18.4R3-S10+11 more2022-10-18
CVE-2022-22223 [HIGH] CWE-1285 CVE-2022-22223: On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penult
On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregation group (LAG) interfaces, an Improper Validation of Specified Index, Position, or Offset in Input weakness allows an attacker sending certain IP packets to cause multiple interfaces in the LAG to detach
nvd
CVE-2022-22205P3HIGHCVSS 7.5≥ 20.3, < 20.3R3-S2≥ 20.4, < 20.4R3-S2+3 more2022-07-20
CVE-2022-22205 [HIGH] CWE-401 CVE-2022-22205: A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Exp
A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). Upon receiving specific traffic a memory leak will occur. Sustained processing of such
nvd
CVE-2023-22415P3HIGHCVSS 7.5≥ unspecified, < 19.4R3-S10≥ 20.2, < 20.2R3-S6+8 more2023-01-13
CVE-2023-22415 [HIGH] CWE-787 CVE-2023-22415: An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthe
An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all MX Series and SRX Series platform, when H.323 ALG is enabled and specific H.323 packets are received simultaneously, a flow processing daemon (flowd) crash will occur. Continued r
nvd
CVE-2025-21598P3HIGHCVSS 7.5≥ 21.2R3-S8, < 21.2R3-S9≥ 21.4R3-S7, < 21.4R3-S9+6 more2025-01-09
CVE-2025-21598 [HIGH] CWE-125 CVE-2025-21598: An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing prot
An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd.
This issue affects:
Junos OS:
* from 21.2R3-S8 before 21.2R3-S9,
* from 2
nvd
CVE-2022-22232P3HIGHCVSS 7.5≥ 21.4, < 21.4R1-S2, 21.4R2≥ 22.1, < 22.1R1-S1, 22.1R22022-10-18
CVE-2022-22232 [HIGH] CWE-476 CVE-2022-22232: A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos O
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific transit traffic is processed the PFE will cras
nvd
CVE-2022-22201P3HIGHCVSS 7.5≥ unspecified, < 19.4R2-S6, 19.4R3-S7≥ 20.1, < 20.1R3-S3+6 more2022-10-18
CVE-2022-22201 [HIGH] CWE-1285 CVE-2022-22201: An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packe
nvd
CVE-2023-28964P3HIGHCVSS 7.5≥ unspecified, < 18.1R3-S11≥ 18.2, < 18.2R3-S6+9 more2023-04-17
CVE-2023-28964 [HIGH] CWE-130 CVE-2023-28964: An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause an RPD crash leading to a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service
nvd
CVE-2023-22417P3HIGHCVSS 7.5≥ unspecified, < 19.3R3-S7≥ 19.4, < 19.4R2-S8, 19.4R3-S10+7 more2023-01-13
CVE-2023-22417 [HIGH] CWE-401 CVE-2023-22417: A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (fl
A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In an IPsec VPN environment, a memory leak will be seen if a DH or ECDH group is configured. Eventually the flowd process will crash a
nvd
CVE-2023-22403P3HIGHCVSS 7.5≥ unspecified, < 20.2R3-S7≥ 20.4, < 20.4R3-S4+5 more2023-01-13
CVE-2023-22403 [HIGH] CWE-770 CVE-2023-22403: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engi
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
On QFX10K Series, Inter-Chassis Control Protocol (ICCP) is used in MC-LAG topologies to exchange control information between the d
nvd