cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 2 of 13
CVE-2025-60004P3HIGHCVSS 7.5≥ 23.4R2-S2-EVO, < 23.4R2-S5-EVO≥ 24.2R2-EVO, < 24.2R2-S1-EVO+1 more2025-10-09
CVE-2025-60004 [HIGH] CWE-754 CVE-2025-60004: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an established BGP session, this cau
nvd
CVE-2021-31356P3HIGHCVSS 7.8≥ unspecified, < 20.4R3-S1-EVO≥ 21.1R1-EVO, < 21.1*+1 more2021-10-19
CVE-2021-31356 [HIGH] CWE-77 CVE-2021-31356: A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass command authorization restrictions assi
nvd
CVE-2021-31357P3HIGHCVSS 7.8≥ unspecified, < 20.3R2-S1-EVO≥ 20.4, < 20.4R2-S2-EVO+2 more2021-10-19
CVE-2021-31357 [HIGH] CWE-77 CVE-2021-31357: A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass command authorization restrict
nvd
CVE-2026-33793P3HIGHCVSS 7.8fixed in 22.4R3-S7-EVO≥ 23.2, < 23.2R2-S4-EVO+3 more2026-04-09
CVE-2026-33793 [HIGH] CWE-250 CVE-2026-33793: An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Network An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute mali
nvd
CVE-2026-33788P3HIGHCVSS 7.8fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S7-EVO+4 more2026-04-09
CVE-2026-33788 [HIGH] CWE-306 CVE-2026-33788: A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a hi
nvd
CVE-2024-30382P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.3, < 21.3R3-EVO+2 more2024-04-12
CVE-2024-30382 [HIGH] CWE-755 CVE-2024-30382: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). This issue can only be triggered whe
nvd
CVE-2024-47499P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.4, < 21.4R3-S8-EVO+5 more2024-10-11
CVE-2024-47499 [HIGH] CWE-754 CVE-2024-47499: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a scenario where BGP Monitoring Protocol (BMP) is configured with rib-in pre-policy monitoring, receiving
nvd
CVE-2024-47502P3HIGHCVSS 7.5fixed in 21.4R3-S9-EVO≥ 22.2, < 22.2R3-S4-EVO+3 more2024-10-11
CVE-2024-47502 [HIGH] CWE-770 CVE-2024-47502: An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Netwo An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In specific cases the state of TCP sessions that are terminated is not cleared, which over time leads to an exhaustion of resources, preventing n
nvd
CVE-2024-39548P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.3, < 21.3R3-S5-EVO+6 more2024-07-11
CVE-2024-39548 [HIGH] CWE-400 CVE-2024-39548: An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting in a Denial of Service (DoS) condition. The processes do not recover on their own and must be manually restarted. This issue affects both IPv4 and IPv6.
nvd
CVE-2024-39531P3HIGHCVSS 7.5fixed in 21.4R3-S7-EVO≥ 22.1, < 22.1R3-S6-EVO+5 more2024-07-11
CVE-2024-39531 [HIGH] CWE-229 CVE-2024-39531: An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networ An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is configured for DDoS bandwidth or burst parameters for any protocol in a queue, all protocols which share the same
nvd
CVE-2024-39562P3HIGHCVSS 7.5fixed in 21.4R3-S7-EVO≥ 22.3-EVO, < 22.3R2-S2-EVO, 22.3R3-S2-EVO+2 more2024-07-10
CVE-2024-39562 [HIGH] CWE-772 CVE-2024-39562: A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by blocking SSH access for legitimate users. Continued receipt of these connections will
nvd
CVE-2024-39516P3HIGHCVSS 7.5≥ 21.4-EVO, < 21.4R3-S9-EVO≥ 22.2-EVO, < 22.2R3-S5-EVO+5 more2024-10-09
CVE-2024-39516 [HIGH] CWE-125 CVE-2024-39516: An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Jun An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a su
nvd
CVE-2025-30651P3HIGHCVSS 7.5fixed in 21.2R3-S9-EVO≥ 21.4-EVO, < 21.4R3-S10-EVO+4 more2025-04-09
CVE-2025-30651 [HIGH] CWE-805 CVE-2025-30651: A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Ju A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a specific ICMPv6 packet to an interface with "protocols router-advertisement" configured, rpd cras
nvd
CVE-2020-1632P3HIGHCVSS 8.6≥ unspecified, < 19.2R2-EVO2020-04-15
CVE-2020-1632 [HIGH] CWE-755 CVE-2020-1632: In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of Service (DoS) condition. For example, Router A sends a specific BGP UPDATE to
nvd
CVE-2024-39522P3HIGHCVSS 7.8≥ 22.3-EVO, < 22.3R2-EVO≥ 22.4-EVO, < 22.4R1-S1-EVO, 22.4R2-EVO2024-07-11
CVE-2024-39522 [HIGH] CWE-78 CVE-2024-39522: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39521P3HIGHCVSS 7.8≥ 21.1-EVO, < 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S7-EVO+3 more2024-07-11
CVE-2024-39521 [HIGH] CWE-78 CVE-2024-39521: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39523P3HIGHCVSS 7.8fixed in 20.4R3-S7-EVO≥ 21.2-EVO, < 21.2R3-S8-EVO+5 more2024-07-11
CVE-2024-39523 [HIGH] CWE-78 CVE-2024-39523: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39520P3HIGHCVSS 7.8fixed in 20.4R3-S6-EVO≥ 21.2-EVO, < 21.2R3-S4-EVO+3 more2024-07-11
CVE-2024-39520 [HIGH] CWE-78 CVE-2024-39520: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2024-39524P3HIGHCVSS 7.8fixed in 20.4R3-S7-EVO≥ 21.2-EVO, < 21.2R3-S8-EVO+4 more2024-07-11
CVE-2024-39524 [HIGH] CWE-78 CVE-2024-39524: An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved co An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system. The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which exe
nvd
CVE-2022-22183P3HIGHCVSS 7.5≥ 20.4, < 20.4R3-S2-EVO≥ 21.1, < 21.1R3-S1-EVO+3 more2022-04-14
CVE-2022-22183 [HIGH] CWE-16 CVE-2022-22183: An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) c
nvd
Juniper Networks Junos OS Evolved vulnerabilities | cvebase