cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 8 of 34
CVE-2024-30405P3HIGHCVSS 7.5fixed in 21.2R3-S7≥ 21.4, < 21.4R3-S6+5 more2024-04-12
CVE-2024-30405 [HIGH] CWE-131 CVE-2024-30405: An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series d An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Continued receipt and processing of these specific packets will sustain the Denial of Service co
nvd
CVE-2023-28976P3HIGHCVSS 7.5≥ unspecified, < 19.1R3-S10≥ 19.2, < 19.2R3-S7+9 more2023-04-17
CVE-2023-28976 [HIGH] CWE-754 CVE-2023-28976: An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If specific traffic is received on MX Series and its rate exceeds the respective DDoS protection limit the ingress PF
nvd
CVE-2023-22401P3HIGHCVSS 7.5≥ 22.1R2, < 22.1*≥ 22.2, < 22.2R22023-01-13
CVE-2023-22401 [HIGH] CWE-129 CVE-2023-22401: An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemo An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On the PTX10008 and PTX10016 platforms running Junos OS or Junos OS Evolved, when a specific SNMP MIB is
nvd
CVE-2023-22411P3HIGHCVSS 7.5≥ 19.2, < 19.2R3-S6≥ 19.3, < 19.3R3-S6+8 more2023-01-13
CVE-2023-22411 [HIGH] CWE-787 CVE-2023-22411: An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On SRX Series devices using Unified Policies with IPv6, when a specific IPv6 packet goes through a dynamic-application filter which will generate an ICMP deny message, th
nvd
CVE-2023-22396P3HIGHCVSS 7.5≥ 12.3R12-S19, < 12.3*≥ 15.1R7-S10, < 15.1*+17 more2023-01-13
CVE-2023-22396 [HIGH] CWE-400 CVE-2023-22396: An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of J An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a Denial of Service (DoS). The system does not recover automatically and mus
nvd
CVE-2024-30395P3HIGHCVSS 7.5fixed in 21.2R3-S7≥ 21.3, < 21.3R3-S5+6 more2024-04-12
CVE-2024-30395 [HIGH] CWE-1287 CVE-2024-30395: An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed
nvd
CVE-2023-44199P3HIGHCVSS 7.5fixed in 20.4R3-S4≥ 21.1R1, < 21.1*+5 more2023-10-13
CVE-2023-44199 [HIGH] CWE-754 CVE-2023-44199: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engi An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lea
nvd
CVE-2023-44186P3HIGHCVSS 7.5fixed in 20.4R3-S8≥ 21.1R1, < 21.1*+7 more2023-10-11
CVE-2023-44186 [HIGH] CWE-755 CVE-2023-44186: An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Netwo An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Continued receipt and processing of these BGP updates will create a sustained
nvd
CVE-2024-21616P3HIGHCVSS 7.5fixed in 21.2R3-S6≥ 21.3, < 21.3R3-S5+6 more2024-01-12
CVE-2024-21616 [HIGH] CWE-1286 CVE-2024-21616: An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX Series and SRX Series platforms, when SIP ALG is enabled, and a specific SIP packet is received and processed, NAT I
nvd
CVE-2023-44197P3HIGHCVSS 7.5fixed in 20.4R3-S8≥ 21.1R1, < 21.1*+3 more2023-10-13
CVE-2023-44197 [HIGH] CWE-787 CVE-2023-44197: An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and restart can occur while processing BGP route updates received over an established
nvd
CVE-2023-44192P3HIGHCVSS 7.5fixed in 20.4R3-S6≥ 21.1, < 21.1R3-S5+7 more2023-10-13
CVE-2023-44192 [HIGH] CWE-20 CVE-2023-44192: An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Juno An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DH
nvd
CVE-2023-36841P3HIGHCVSS 7.5fixed in 20.4R3-S7≥ 21.1R1, < 21.1*+7 more2023-10-12
CVE-2023-36841 [HIGH] CWE-400 CVE-2023-36841: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engi An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, caus
nvd
CVE-2025-52980P3HIGHCVSS 7.5≥ 22.2, < 22.2R3-S4≥ 22.3, < 22.3R3-S3+3 more2025-07-11
CVE-2025-52980 [HIGH] CWE-198 CVE-2025-52980: A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper N A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an established BGP session which contains a specific, valid, optional, transitive path attribute, rpd
nvd
CVE-2024-39530P3HIGHCVSS 7.5≥ 21.4R3, < 21.4R3-S5≥ 22.1R3, < 22.1R3-S4+3 more2024-07-11
CVE-2024-39530 [HIGH] CWE-754 CVE-2024-39530: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daem An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an attempt is made to access specific sensors on platforms not supporting these sensors, either via GRPC or netconf, ch
nvd
CVE-2024-39515P3HIGHCVSS 7.5fixed in 21.4R3-S8≥ 22.2, < 22.2R3-S5+4 more2024-10-09
CVE-2024-39515 [HIGH] CWE-1288 CVE-2024-39515: An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing
nvd
CVE-2024-39516P3HIGHCVSS 7.5≥ 21.4, < 21.4R3-S9≥ 22.2, < 22.2R3-S5+5 more2024-10-09
CVE-2024-39516 [HIGH] CWE-125 CVE-2024-39516: An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Jun An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a su
nvd
CVE-2025-59964P3HIGHCVSS 7.5≥ 24.4, < 24.4R1-S3, 24.4R22025-10-09
CVE-2025-59964 [HIGH] CWE-908 CVE-2025-59964: A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Netwo A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When forwarding-options sampling is enabled, receipt of any traffic destined to the Routing Engine (RE) by the PFE line card leads to
nvd
CVE-2024-30397P3HIGHCVSS 7.5fixed in 20.4R3-S10≥ 21.2, < 21.2R3-S7+6 more2024-04-12
CVE-2024-30397 [HIGH] CWE-754 CVE-2024-30397: An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastr An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). The pkid is responsible for the certificate verification. Upon a failed verification, the pkid uses all CPU resources and b
nvd
CVE-2025-30644P3HIGHCVSS 7.5fixed in 21.4R3-S9≥ 22.2, < 22.2R3-S5+4 more2025-04-09
CVE-2025-30644 [HIGH] CWE-122 CVE-2025-30644: A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Network A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Continued
nvd
CVE-2025-59980P3MEDIUMCVSS 6.5fixed in 22.4R3-S8≥ 23.2, < 23.2R2-S3+1 more2025-10-09
CVE-2025-59980 [MEDIUM] CWE-305 CVE-2025-59980: An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can login without providing the configured password and the
nvd
Juniper Networks Junos Os vulnerabilities | cvebase