cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 11 of 13
CVE-2021-0287P4MEDIUMCVSS 6.5≥ 19.4R1-EVO, < 19.4*≥ 20.1R1-EVO, < 20.1*+3 more2021-07-15
CVE-2021-0287 [MEDIUM] CWE-754 CVE-2021-0287: In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evol In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued link f
nvd
CVE-2024-39560P4MEDIUMCVSS 6.5fixed in 21.4R3-S5-EVO≥ 22.1-EVO, < 22.1R3-S5-EVO+4 more2024-07-10
CVE-2024-39560 [MEDIUM] CWE-755 CVE-2024-39560: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent downstream RSVP neighbor to cause kernel memory exhaustion, leading to a kernel crash, resulting in a Denial of Service (DoS). The kernel memory leak and eventual crash will
nvd
CVE-2024-39557P4MEDIUMCVSS 6.5fixed in 21.4R3-S8-EVO≥ 22.2-EVO, < 22.2R3-S4-EVO+3 more2024-07-10
CVE-2024-39557 [MEDIUM] CWE-400 CVE-2024-39557: An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS). Certain MAC table updates cause a small amount of m
nvd
CVE-2024-39532P4MEDIUMCVSS 6.3fixed in 22.1R3-EVO≥ 22.2-EVO, < 22.2R2-S1-EVO, 22.2R3-EVO+1 more2024-07-11
CVE-2024-39532 [MEDIUM] CWE-532 CVE-2024-39532: An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and J An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. When another user performs a specific operation, sensitive information is stored as plain text in a specific log file, so that a high-privile
nvd
CVE-2024-39534P4MEDIUMCVSS 5.4fixed in 21.4R3-S8-EVO≥ 22.2-EVO, < 22.2R3-S4-EVO+4 more2024-10-11
CVE-2024-39534 [MEDIUM] CWE-697 CVE-2024-39534: An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Juno An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface. This is unintended and unexpected behavior and can allow
nvd
CVE-2020-1681P4MEDIUMCVSS 6.5≥ all, < 20.1R2-EVO2020-10-16
CVE-2020-1681 [MEDIUM] CWE-755 CVE-2020-1681: Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device ru Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS). The process automatically restarts without intervention, but a continuous receipt of the malformed NDP packets could leaded to an extende
nvd
CVE-2020-1678P4MEDIUMCVSS 6.5v19.4-EVO≥ 20.1-EVO, < 20.1R1-S4-EVO, 20.1R2-EVO2020-10-16
CVE-2020-1678 [MEDIUM] CWE-400 CVE-2020-1678: On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specifi On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the memory is exhausted the rpd process might crash. If the issue occurs, the memory leak could be seen by executing the "show task memory detail | match policy | match evpn" command multiple times to check if
nvd
CVE-2025-30654P4MEDIUMCVSS 5.5fixed in 21.4R3-S10-EVO≥ 22.2-EVO, < 22.2R3-S6-EVO+3 more2025-04-09
CVE-2025-30654 [MEDIUM] CWE-200 CVE-2025-30654: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (U An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Through the execution of a specific show mgd command, a user with limited permissions
nvd
CVE-2026-57029P4MEDIUMCVSS 5.3fixed in 23.4R2-S7-EVO≥ 24.2, < 24.2R2-S5-EVO+2 more2026-07-09
CVE-2026-57029 [MEDIUM] CWE-820 CVE-2026-57029: A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS E A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFl
nvd
CVE-2023-22397P4MEDIUMCVSS 6.1≥ unspecified, < 20.4R3-S4-EVO≥ 21.3, < 21.3R3-S1-EVO+3 more2023-01-13
CVE-2023-22397 [MEDIUM] CWE-367 CVE-2023-22397: An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Pac An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks Junos OS Evolved PTX10003 Series devices allows an adjacently located attacker who has established certain preconditions and knowledge of the environment to send certain specific genuine packets to begin
nvd
CVE-2023-36840P4MEDIUMCVSS 5.5≥ unspecified, < 20.4R3-S7-EVO≥ 21.1, < 21.1R3-S3-EVO+6 more2023-07-14
CVE-2023-36840 [MEDIUM] CWE-617 CVE-2023-36840: A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS an A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved, when a specific L2VPN command is run, RPD will crash and restart. Continued execution of this specific comman
nvd
CVE-2023-44177P4MEDIUMCVSS 5.5fixed in 20.4R3-S8-EVO≥ 21.2, < 21.2R3-S6-EVO+6 more2023-10-13
CVE-2023-44177 [MEDIUM] CWE-121 CVE-2023-44177: A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS: * All ve
nvd
CVE-2026-57025P4MEDIUMCVSS 5.5fixed in 23.2R2-S7-EVO≥ 23.4, < 23.4R2-S8-EVO+2 more2026-07-09
CVE-2026-57025 [MEDIUM] CWE-466 CVE-2026-57025: A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper N A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' comma
nvd
CVE-2023-44189P4MEDIUMCVSS 5.4fixed in 21.4R3-S4-EVO≥ 22.1, < 22.1R3-S3-EVO+4 more2023-10-11
CVE-2023-44189 [MEDIUM] CWE-346 CVE-2023-44189: An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved o An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if
nvd
CVE-2023-44190P4MEDIUMCVSS 5.4fixed in 21.4R3-S5-EVO≥ 22.1, < 22.1R3-S4-EVO+4 more2023-10-11
CVE-2023-44190 [MEDIUM] CWE-346 CVE-2023-44190: An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved o An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the route
nvd
CVE-2024-30386P4MEDIUMCVSS 5.3fixed in 20.4R3-S8-EVO≥ 21.2-EVO, < 21.2R3-S6-EVO+6 more2024-04-12
CVE-2024-30386 [MEDIUM] CWE-416 CVE-2024-30386: A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause l2ald to crash leading to a Denial-of-Service (DoS). In an EVPN-VXLAN scenario, when state updates are received and processed by the affected system, the correct order o
nvd
CVE-2025-59962P4MEDIUMCVSS 5.3≥ 22.3, < 22.3R3-S3-EVO≥ 22.4, < 22.4R3-EVO+1 more2025-10-09
CVE-2025-59962 [MEDIUM] CWE-824 CVE-2025-59962: An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Net An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a Denial of Service (DoS). With
nvd
CVE-2025-52989P4MEDIUMCVSS 5.1fixed in 22.4R3-S7-EVO≥ 23.2-EVO, < 23.2R2-S4-EVO+3 more2025-07-11
CVE-2025-52989 [MEDIUM] CWE-140 CVE-2025-52989: An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Ju An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part
nvd
CVE-2020-1666P4MEDIUMCVSS 6.6≥ unspecified, < 20.2R1-EVO2020-10-16
CVE-2020-1666 [MEDIUM] CWE-284 CVE-2020-1666: The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a previous interactive session and possibly gain administrative privileges. T
nvd
CVE-2022-22215P4MEDIUMCVSS 5.5≥ unspecified, < 20.4R3-EVO≥ 21.1, < 21.1R3-S1-EVO+1 more2022-07-20
CVE-2022-22215 [MEDIUM] CWE-772 CVE-2022-22215: A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable au A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). It is possible that after the termination of a gRPC connection the respective/v
nvd