Juniper Networks Junos OS Evolved vulnerabilities
246 known vulnerabilities affecting juniper_networks/junos_os_evolved.
Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145
Vulnerabilities
Page 13 of 13
CVE-2020-1622P4MEDIUMCVSS 5.5≥ unspecified, < 19.1R1-EVO2020-04-08
CVE-2020-1622 [MEDIUM] CWE-664 CVE-2020-1622: A local, authenticated user with shell can obtain the hashed values of login passwords and shared se
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
nvd
CVE-2020-1621P4MEDIUMCVSS 5.5≥ unspecified, < 19.3R1-EVO2020-04-08
CVE-2020-1621 [MEDIUM] CWE-664 CVE-2020-1621: A local, authenticated user with shell can obtain the hashed values of login passwords via configd t
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
nvd
CVE-2024-21615P4MEDIUMCVSS 5.0fixed in 21.2R3-S7-EVO≥ 21.3-EVO, < 21.3R3-S5-EVO+6 more2024-04-12
CVE-2024-21615 [MEDIUM] CWE-276 CVE-2024-21615: An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved all
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system.
On all Junos OS and Junos OS Evolved platforms, when NETCONF traceoptions are configured, and a super-user performs specific actions via NETCONF, then a low-privil
nvd
CVE-2023-36836P4MEDIUMCVSS 4.7≥ unspecified, < 20.4R3-S6-EVO≥ 21.1, < 21.1*+5 more2023-07-14
CVE-2023-36836 [MEDIUM] CWE-908 CVE-2023-36836: A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Net
A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, in a Multicast only Fast Reroute (MoFRR) scenario, the rpd process can
nvd
CVE-2021-0298P4MEDIUMCVSS 4.7≥ unspecified, < 20.1R2-EVO2021-10-19
CVE-2021-0298 [MEDIUM] CWE-362 CVE-2021-0298: A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an
A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS) condition. Continued execution of th
nvd
CVE-2026-21901P4MEDIUMCVSS 4.4≥ 23.2, < 23.2R2-S7-EVO≥ 23.4, < 23.4R2-S8-EVO2026-07-09
CVE-2026-21901 [MEDIUM] CWE-476 CVE-2026-21901: A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).
A local high-privileged user configuring or deactivating a specific 'system services ss
nvd
← Previous13 / 13