cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 2 of 13
CVE-2025-52954P3HIGHCVSS 7.8fixed in 22.2R3-S7-EVO≥ 22.4, < 22.4R3-S7-EVO+4 more2025-07-11
CVE-2025-52954 [HIGH] CWE-862 CVE-2025-52954: A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Junipe A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise. Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify t
nvd
CVE-2021-31356P3HIGHCVSS 7.8≥ unspecified, < 20.4R3-S1-EVO≥ 21.1R1-EVO, < 21.1*+1 more2021-10-19
CVE-2021-31356 [HIGH] CWE-77 CVE-2021-31356: A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass command authorization restrictions assi
nvd
CVE-2021-31357P3HIGHCVSS 7.8≥ unspecified, < 20.3R2-S1-EVO≥ 20.4, < 20.4R2-S2-EVO+2 more2021-10-19
CVE-2021-31357 [HIGH] CWE-77 CVE-2021-31357: A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass command authorization restrict
nvd
CVE-2024-30382P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.3, < 21.3R3-EVO+2 more2024-04-12
CVE-2024-30382 [HIGH] CWE-755 CVE-2024-30382: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). This issue can only be triggered whe
nvd
CVE-2024-30394P3HIGHCVSS 7.5fixed in 21.4R3-S5-EVO≥ 22.1-EVO, < 22.1R3-S4-EVO+4 more2024-04-12
CVE-2024-30394 [HIGH] CWE-121 CVE-2024-30394: A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when EVPN is configured, and a specific EVPN type-5 route is received vi
nvd
CVE-2024-47502P3HIGHCVSS 7.5fixed in 21.4R3-S9-EVO≥ 22.2, < 22.2R3-S4-EVO+3 more2024-10-11
CVE-2024-47502 [HIGH] CWE-770 CVE-2024-47502: An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Netwo An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In specific cases the state of TCP sessions that are terminated is not cleared, which over time leads to an exhaustion of resources, preventing n
nvd
CVE-2024-47499P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.4, < 21.4R3-S8-EVO+5 more2024-10-11
CVE-2024-47499 [HIGH] CWE-754 CVE-2024-47499: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a scenario where BGP Monitoring Protocol (BMP) is configured with rib-in pre-policy monitoring, receiving
nvd
CVE-2024-39548P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.3, < 21.3R3-S5-EVO+6 more2024-07-11
CVE-2024-39548 [HIGH] CWE-400 CVE-2024-39548: An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting in a Denial of Service (DoS) condition. The processes do not recover on their own and must be manually restarted. This issue affects both IPv4 and IPv6.
nvd
CVE-2024-39531P3HIGHCVSS 7.5fixed in 21.4R3-S7-EVO≥ 22.1, < 22.1R3-S6-EVO+5 more2024-07-11
CVE-2024-39531 [HIGH] CWE-229 CVE-2024-39531: An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networ An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is configured for DDoS bandwidth or burst parameters for any protocol in a queue, all protocols which share the same
nvd
CVE-2024-39562P3HIGHCVSS 7.5fixed in 21.4R3-S7-EVO≥ 22.3-EVO, < 22.3R2-S2-EVO, 22.3R3-S2-EVO+2 more2024-07-10
CVE-2024-39562 [HIGH] CWE-772 CVE-2024-39562: A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by blocking SSH access for legitimate users. Continued receipt of these connections will
nvd
CVE-2025-60004P3HIGHCVSS 7.5≥ 23.4R2-S2-EVO, < 23.4R2-S5-EVO≥ 24.2R2-EVO, < 24.2R2-S1-EVO+1 more2025-10-09
CVE-2025-60004 [HIGH] CWE-754 CVE-2025-60004: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an established BGP session, this cau
nvd
CVE-2025-30651P3HIGHCVSS 7.5fixed in 21.2R3-S9-EVO≥ 21.4-EVO, < 21.4R3-S10-EVO+4 more2025-04-09
CVE-2025-30651 [HIGH] CWE-805 CVE-2025-30651: A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Ju A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a specific ICMPv6 packet to an interface with "protocols router-advertisement" configured, rpd cras
nvd
CVE-2020-1632P3HIGHCVSS 8.6≥ unspecified, < 19.2R2-EVO2020-04-15
CVE-2020-1632 [HIGH] CWE-755 CVE-2020-1632: In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of Service (DoS) condition. For example, Router A sends a specific BGP UPDATE to
nvd
CVE-2022-22183P3HIGHCVSS 7.5≥ 20.4, < 20.4R3-S2-EVO≥ 21.1, < 21.1R3-S1-EVO+3 more2022-04-14
CVE-2022-22183 [HIGH] CWE-16 CVE-2022-22183: An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) c
nvd
CVE-2024-39522P3HIGHCVSS 7.8≥ 22.3-EVO, < 22.3R2-EVO≥ 22.4-EVO, < 22.4R1-S1-EVO, 22.4R2-EVO2024-07-11
CVE-2024-39522 [HIGH] CWE-78 CVE-2024-39522: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39521P3HIGHCVSS 7.8≥ 21.1-EVO, < 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S7-EVO+3 more2024-07-11
CVE-2024-39521 [HIGH] CWE-78 CVE-2024-39521: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39523P3HIGHCVSS 7.8fixed in 20.4R3-S7-EVO≥ 21.2-EVO, < 21.2R3-S8-EVO+5 more2024-07-11
CVE-2024-39523 [HIGH] CWE-78 CVE-2024-39523: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39520P3HIGHCVSS 7.8fixed in 20.4R3-S6-EVO≥ 21.2-EVO, < 21.2R3-S4-EVO+3 more2024-07-11
CVE-2024-39520 [HIGH] CWE-78 CVE-2024-39520: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39524P3HIGHCVSS 7.8fixed in 20.4R3-S7-EVO≥ 21.2-EVO, < 21.2R3-S8-EVO+4 more2024-07-11
CVE-2024-39524 [HIGH] CWE-78 CVE-2024-39524: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2022-22212P3HIGHCVSS 7.5≥ 21.2, < 21.2R3-EVO≥ 21.3, < 21.3R2-EVO2022-07-20
CVE-2022-22212 [HIGH] CWE-770 CVE-2022-22212: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engin An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos Evolved platforms hostbound protocols will be impacted by a high rate of specific hostbound traffic from ports on
nvd
Juniper Networks Junos OS Evolved vulnerabilities | cvebase