cbcvebase.

Juniper Networks Junos Os vulnerabilities

670 known vulnerabilities affecting juniper_networks/junos_os.

Total CVEs
670
CISA KEV
7
actively exploited
Public exploits
6
Exploited in wild
10
Severity breakdown
CRITICAL34HIGH298MEDIUM338

Vulnerabilities

Page 9 of 34
CVE-2019-0001P3HIGHCVSS 7.5≥ 16.1, < 16.1R7-S1≥ 16.2, < 16.2R2-S7+6 more2019-01-15
CVE-2019-0001 [HIGH] CWE-674 CVE-2019-0001: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an un Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeated receipt of the same packet can result in an extended denial of service condition for the devi
nvd
CVE-2016-4921P3HIGHCVSS 7.5v11.4 prior to 11.4R13-S3v12.3 prior to 12.3R3-S4+9 more2017-10-13
CVE-2016-4921 [HIGH] CWE-399 CVE-2016-4921: By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all avai By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may result in a total resource exhaustion and kernel panic. The issue is triggered by traffic destin
nvd
CVE-2019-0010P3HIGHCVSS 7.5≥ 12.1X46, < 12.1X46-D81≥ 12.3X48, < 12.3X48-D77+1 more2019-01-15
CVE-2019-0010 [HIGH] CWE-770 CVE-2019-0010: An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer exhaustion -- due to the receipt of crafted HTTP traffic. Each crafted HTTP packet inspected by UTM consumes mbufs which can be identified through the following log messages: al
nvd
CVE-2018-0022P3HIGHCVSS 7.5≥ 12.1X46, < 12.1X46-D76≥ 12.3X48, < 12.3X48-D66, 12.3X48-D70+13 more2018-04-11
CVE-2018-0022 [HIGH] CWE-400 CVE-2018-0022: A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible t A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is platform dependent. The following command provides the number of mbufs that are currently in use and maximum number of
nvd
CVE-2019-0052P3HIGHCVSS 7.5v12.3X48 versions prior to 12.3X48-D85 on SRX Seriesv15.1X49 versions prior to 15.1X49-D181 and 15.1X49-D190 on SRX Series+6 more2019-07-11
CVE-2019-0052 [HIGH] CWE-404 CVE-2019-0052: The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specifi The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterpreted as a regular TCP packet which causes the processor to crash. This issue affects all SRX Series platforms that support URL-Filtering and have web-filtering enabled. Affected releases are Juniper Networ
nvd
CVE-2018-0026P3HIGHCVSS 7.5v15.1R4, 15.1R5, 15.1R6≥ 15.1X8, < 15.1X8.32018-07-11
CVE-2018-0026 [HIGH] CVE-2018-0026: After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take ef After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can be verified by running the command: user@re0> show interfaces extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Note: when the issue occurs, it does not show the applied firewall filter. The correct output should sh
nvd
CVE-2019-0031P3HIGHCVSS 7.5≥ 17.4, < 17.4R2≥ 18.1, < 18.1R22019-04-10
CVE-2019-0031 [HIGH] CWE-400 CVE-2019-0031: Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption is Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcpd daemon configured to respond to IPv6 requests. Once started, memory consumption will eventually impact any IPv4 or IPv6 request serviced by the jdhcpd daemon, thus creating a Denial of Service (DoS) condi
nvd
CVE-2021-0278P3HIGHCVSS 7.8≥ 19.3R1, < 19.3*≥ 19.4, < 19.4R3-S5+5 more2021-07-15
CVE-2021-0278 [HIGH] CWE-20 CVE-2021-0278: An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally au An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S3 junos:19.4R1-S4 junos:19.4R3-S4 junos:20.1R2-S2 junos:20.1R3 junos:20.2R3-S1 junos:20.3X75-D20
nvd
CVE-2019-0012P3HIGHCVSS 7.5≥ 12.1X46, < 12.1X46-D81≥ 12.3, < 12.3R12-S12+12 more2019-01-15
CVE-2019-0012 [HIGH] CVE-2019-0012: A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker to craft a specific BGP message to cause the routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. This issue only affects PE routers configured wi
nvd
CVE-2020-1617P3HIGHCVSS 7.5≥ 17.4, < 17.4R2-S9, 17.4R3≥ 18.1, ≤ 18.1R3-S9+3 more2020-04-08
CVE-2020-1617 [HIGH] CWE-665 CVE-2020-1617: This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Inte This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to this issue. An improper initialization of memory in the packet forwarding architecture in Juniper Networks Junos OS non-AFI/AFT platforms which may lead to a
nvd
CVE-2021-31379P3HIGHCVSS 7.5≥ 17.2R1, < 17.2*≥ 17.3, < 17.3R3-S9+8 more2021-10-19
CVE-2021-31379 [HIGH] CWE-696 CVE-2021-31379: An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Netw An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as a result of the processing of these packets. Continued receipt and processing of these malfo
nvd
CVE-2021-0206P3HIGHCVSS 7.5≥ 18.3R1, < 18.3*≥ 18.4, < 18.4R3-S1+3 more2021-01-15
CVE-2021-0206 [HIGH] CWE-476 CVE-2021-0206: A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a s A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS). By continuously sending these specific packets, an attacker can repeatedly disable the PFE causing a sustained Denial of Service (DoS).
nvd
CVE-2021-0207P3HIGHCVSS 7.5≥ 17.3, < 17.3R3-S7≥ 17.4, < 17.4R2-S11, 17.4R3-S3+8 more2021-01-15
CVE-2021-0207 [HIGH] CWE-115 CVE-2021-0207: An improper interpretation conflict of certain data between certain software components within the J An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering certain specific types of traffic which is then being redirected to an egress interface on a different VLAN. This c
nvd
CVE-2016-4922P3HIGHCVSS 7.8v11.4 prior to 11.4R13-S3v12.1X46 prior to 12.1X46-D60+12 more2017-10-13
CVE-2016-4922 [HIGH] CWE-77 CVE-2016-4922: Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a w Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevated privileges and gain complete control of the device. Affected releases are Juniper Networks Jun
nvd
CVE-2021-31368P3HIGHCVSS 7.5≥ unspecified, < 18.1R3-S13≥ 18.2, < 18.2R3-S8+10 more2021-10-19
CVE-2021-31368 [HIGH] CWE-400 CVE-2021-31368: An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port. Continued receipted of a flood will create a sustained Denial of Service (
nvd
CVE-2021-31383P3HIGHCVSS 7.5≥ 19.2, < 19.2R3-S2≥ 19.3, < 19.3R2-S6, 19.3R3-S2+4 more2021-10-19
CVE-2021-31383 [HIGH] CWE-121 CVE-2021-31383: In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neig In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved sent by a rem
nvd
CVE-2021-31359P3HIGHCVSS 7.8≥ 15.1, < 15.1R7-S10≥ 17.4, < 17.4R3-S5+11 more2021-10-19
CVE-2021-31359 [HIGH] CWE-121 CVE-2021-31359: A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. Continued processing of malicious input will repeatedly crash the system and sustain t
nvd
CVE-2021-0284P3HIGHCVSS 7.5≥ 12.3, < 12.3R12-S19≥ 15.1, < 15.1R7-S10+12 more2021-08-17
CVE-2021-0284 [HIGH] CWE-120 CVE-2021-0284: A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of Service (DoS). By repeatedly sending these sequences of packets to the device, an attacker can sustain the Denial of Service (DoS) condition. The device will abnormally shut do
nvd
CVE-2022-22161P3HIGHCVSS 7.5≥ unspecified, < 18.3R3-S6≥ 18.4, < 18.4R2-S9, 18.4R3-S9+10 more2022-01-19
CVE-2022-22161 [HIGH] CWE-400 CVE-2022-22161: An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port. Continued receipted of a flood will create a sustained Denial of Service (
nvd
CVE-2022-22221P3HIGHCVSS 7.8≥ unspecified, < 19.1R3-S9≥ 19.2, < 19.2R1-S9, 19.2R3-S5+10 more2022-07-20
CVE-2022-22221 [HIGH] CVE-2022-22221: An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Netw An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Networks Junos OS on SRX Series and EX Series allows a locally authenticated attacker with low privileges to take full control over the device. One aspect of this vulnerability is that the attacker needs to be able to execute any of the "request ..." or "show syste
nvd
Juniper Networks Junos Os vulnerabilities | cvebase