cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 3 of 13
CVE-2021-31383P3HIGHCVSS 7.5≥ 20.1, < 20.1R3-EVO≥ 20.2, < 20.2R3-EVO+1 more2021-10-19
CVE-2021-31383 [HIGH] CWE-121 CVE-2021-31383: In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neig In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved sent by a rem
nvd
CVE-2022-22212P3HIGHCVSS 7.5≥ 21.2, < 21.2R3-EVO≥ 21.3, < 21.3R2-EVO2022-07-20
CVE-2022-22212 [HIGH] CWE-770 CVE-2022-22212: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engin An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos Evolved platforms hostbound protocols will be impacted by a high rate of specific hostbound traffic from ports on
nvd
CVE-2025-21598P3HIGHCVSS 7.5≥ 21.4R3-S7-EVO, < 21.4R3-S9-EVO≥ 22.2R3-S4-EVO, < 22.2R3-S5-EVO+5 more2025-01-09
CVE-2025-21598 [HIGH] CWE-125 CVE-2025-21598: An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing prot An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects: Junos OS: * from 21.2R3-S8 before 21.2R3-S9, * from 2
nvd
CVE-2022-22192P3HIGHCVSS 7.5≥ 20.4-EVO, < 20.4R3-S4-EVO≥ 21.3-EVO, < 21.3R3-EVO+2 more2022-10-18
CVE-2022-22192 [HIGH] CWE-1286 CVE-2022-22192: An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Netw An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming TCP packet destined to the device is malformed there is a possibility of a kernel panic. Only TCP packets destined
nvd
CVE-2023-28964P3HIGHCVSS 7.5≥ unspecified, < 20.1R3-EVO≥ 20.2, < 20.2R2-EVO+1 more2023-04-17
CVE-2023-28964 [HIGH] CWE-130 CVE-2023-28964: An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause an RPD crash leading to a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service
nvd
CVE-2023-22401P3HIGHCVSS 7.5≥ 21.3R3-EVO, < 21.3-EVO*≥ 21.4R1-S2-EVO, 21.4R2-EVO, < 21.4-EVO*+2 more2023-01-13
CVE-2023-22401 [HIGH] CWE-129 CVE-2023-22401: An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemo An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On the PTX10008 and PTX10016 platforms running Junos OS or Junos OS Evolved, when a specific SNMP MIB is
nvd
CVE-2022-22247P3HIGHCVSS 7.5≥ 21.3-EVO, < 21.3R3-EVO≥ 21.4-EVO, < 21.4R2-EVO+1 more2022-10-18
CVE-2022-22247 [HIGH] CWE-20 CVE-2022-22247: An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Jun An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker to send a crafted TCP segment to the device, triggering a kernel panic, leading to a Denial of Service (DoS) condition. Continued receipt and processing of this TCP segment could create a sust
nvd
CVE-2024-30395P3HIGHCVSS 7.5fixed in 21.2R3-S7-EVO≥ 21.3-EVO, < 21.3R3-S5-EVO+5 more2024-04-12
CVE-2024-30395 [HIGH] CWE-1287 CVE-2024-30395: An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed
nvd
CVE-2023-44186P3HIGHCVSS 7.5fixed in 20.4R3-S8-EVO≥ 21.1, < 21.1*-EVO+7 more2023-10-11
CVE-2023-44186 [HIGH] CWE-755 CVE-2023-44186: An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Netwo An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Continued receipt and processing of these BGP updates will create a sustained
nvd
CVE-2024-21612P3HIGHCVSS 7.5fixed in 21.2R3-S7-EVO≥ 21.3, < 21.3R3-S5-EVO +5 more2024-01-12
CVE-2024-21612 [HIGH] CWE-228 CVE-2024-21612: An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protoc An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS Evolved platforms, when specific TCP packets are received on an open OFP port, the OFP crashes leading to
nvd
CVE-2023-44197P3HIGHCVSS 7.5fixed in 20.4R3-S8-EVO≥ 21.1R1-EVO, < 21.1*-EVO+3 more2023-10-13
CVE-2023-44197 [HIGH] CWE-787 CVE-2023-44197: An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and restart can occur while processing BGP route updates received over an established
nvd
CVE-2024-39515P3HIGHCVSS 7.5fixed in 21.4R3-S8-EVO≥ 22.2-EVO, < 22.2R3-S5-EVO+4 more2024-10-09
CVE-2024-39515 [HIGH] CWE-1288 CVE-2024-39515: An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing
nvd
CVE-2022-22195P3HIGHCVSS 7.5≥ unspecified, < 20.4R3-S1-EVO≥ 21.1, < 21.1R3-EVO+2 more2022-04-14
CVE-2022-22195 [HIGH] CWE-911 CVE-2022-22195: An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolv An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS). This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S1-EVO; 21.1 versions prior to 21.1R3-EV
nvd
CVE-2021-31359P3HIGHCVSS 7.8≥ unspecified, < 20.4R2-S3-EVO≥ 21.1R1-EVO, < 21.1*2021-10-19
CVE-2021-31359 [HIGH] CWE-121 CVE-2021-31359: A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. Continued processing of malicious input will repeatedly crash the system and sustain t
nvd
CVE-2022-22177P3HIGHCVSS 7.5≥ unspecified, < 21.2R3-EVO≥ 21.3, < 21.3R2-EVO2022-01-19
CVE-2022-22177 [HIGH] CWE-755 CVE-2022-22177: A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impacts any version of SNMP – v1,v2, v3 This issue affects: Juniper Networks Junos OS 12.3 version
nvd
CVE-2023-28966P3HIGHCVSS 7.8≥ unspecified, < 20.4R3-S5-EVO≥ 21.2, < 21.2R3-EVO+1 more2023-04-17
CVE-2023-28966 [HIGH] CWE-276 CVE-2023-28966: An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-pri An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system files, allowing an attacker with access to these files and folders to inject
nvd
CVE-2024-21614P3HIGHCVSS 7.5≥ 22.2, < 22.2R2-S2-EVO, 22.2R3-EVO≥ 22.3, < 22.3R2-EVO, 22.3R3-EVO2024-01-12
CVE-2024-21614 [HIGH] CWE-754 CVE-2024-21614: An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (R An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause rpd to crash, leading to Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when NETCONF and gRPC are enabled, and a spe
nvd
CVE-2022-22184P3HIGHCVSS 7.5≥ 22.3-EVO, < 22.3R1-S1-EVO2022-12-22
CVE-2022-22184 [HIGH] CWE-20 CVE-2022-22184: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, th
nvd
CVE-2023-0026P3HIGHCVSS 7.5≥ unspecified, < 20.4R3-S8-EVO≥ 21.1R1-EVO, < 21.1*+8 more2023-06-21
CVE-2023-0026 [HIGH] CWE-20 CVE-2023-0026: An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, t
nvd
CVE-2023-28982P3HIGHCVSS 7.5≥ 20.3R1-EVO, < 20.3-EVO*≥ 20.4-EVO, < 20.4R3-S6-EVO+2 more2023-04-17
CVE-2023-28982 [HIGH] CWE-401 CVE-2023-28982: A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scenario, when an attribute of an active BGP route is updated memory will leak. As rpd memory usa
nvd