Juniper Networks Junos OS Evolved vulnerabilities
246 known vulnerabilities affecting juniper_networks/junos_os_evolved.
Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145
Vulnerabilities
Page 4 of 13
CVE-2023-28967P3HIGHCVSS 7.5≥ 21.1R1-EVO, < 21.1-EVO*≥ 21.4-EVO, < 21.4R3-EVO+2 more2023-04-17
CVE-2023-28967 [HIGH] CWE-908 CVE-2023-28967: A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Junip
A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial of Service (DoS) by crashing the Routing Protocol Daemon (rpd). This issue
nvd
CVE-2023-22400P3HIGHCVSS 7.5≥ unspecified, < 20.4R3-S3-EVO≥ 21.1R1-EVO, < 21.1-EVO*+3 more2023-01-13
CVE-2023-22400 [HIGH] CWE-400 CVE-2023-22400: An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Jun
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or a specific CLI command is executed this will cause a GUID resource leak, e
nvd
CVE-2025-21599P3HIGHCVSS 7.5≥ 22.4-EVO, < 22.4R3-S5-EVO≥ 23.2-EVO, < 23.2R2-S2-EVO+2 more2025-01-09
CVE-2025-21599 [HIGH] CWE-401 CVE-2025-21599: A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd
A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service.
Receipt of specifically malformed IPv6 packets, destined to the device, causes kernel memory to not be freed, resulting in memory exhaus
nvd
CVE-2024-39552P3HIGHCVSS 7.5fixed in 21.2R3-S7-EVO≥ 21.3-EVO, < 21.3R3-S5-EVO+7 more2024-07-11
CVE-2024-39552 [HIGH] CWE-755 CVE-2024-39552: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the RPD process to crash leading to a Denial of Service (DoS).
When a malformed BGP UPDATE packet is received over an established BGP session, RPD
nvd
CVE-2024-21611P3HIGHCVSS 7.5≥ 21.4-EVO, < 21.4R3-EVO≥ 22.1-EVO, < 22.1R3-EVO+1 more2024-01-12
CVE-2024-21611 [HIGH] CWE-401 CVE-2024-21611: A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (
A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
In a Juniper Flow Monitoring (jflow) scenario route churn that causes BGP next hops to be updated will cause a sl
nvd
CVE-2024-21598P3HIGHCVSS 7.5≥ 20.4-EVO, < 20.4R3-S9-EVO≥ 21.2-EVO, < 21.2R3-S7-EVO+7 more2024-04-12
CVE-2024-21598 [HIGH] CWE-1286 CVE-2024-21598: An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemo
An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute
nvd
CVE-2024-21604P3HIGHCVSS 7.5fixed in 20.4R3-S7-EVO≥ 21.2-EVO, < 21.2*-EVO+5 more2024-01-12
CVE-2024-21604 [HIGH] CWE-770 CVE-2024-21604: An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Netw
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
If a high rate of specific valid packets are processed by the routing engine (RE) this will lead to a loss of connectivity of the RE with other co
nvd
CVE-2024-21602P3HIGHCVSS 7.5≥ 21.4-EVO, < 21.4R3-S6-EVO≥ 22.1-EVO, < 22.1R3-S5-EVO+2 more2024-01-12
CVE-2024-21602 [HIGH] CWE-476 CVE-2024-21602: A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-3
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
If a specific IPv4 UDP packet is received and sent to the Routing Engine (RE) packetio crashes and restarts which causes a momentary traffic interrup
nvd
CVE-2023-44185P3HIGHCVSS 7.5fixed in 20.4R3-S6-EVO≥ 21.1R1-EVO, < 21.1*-EVO+6 more2023-10-13
CVE-2023-44185 [HIGH] CWE-20 CVE-2023-44185: An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks
An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (DoS )to the device upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet.
Continued receipt of this packet will cause a sustained Denial of Service condition.
This issue affects:
nvd
CVE-2023-44175P3HIGHCVSS 7.5fixed in 22.3R3-EVO≥ 22.4-EVO, < 22.4R3-EVO+1 more2023-10-12
CVE-2023-44175 [HIGH] CWE-617 CVE-2023-44175: A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (DoS).
Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
Note
nvd
CVE-2024-39525P3HIGHCVSS 7.5fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S8-EVO+5 more2024-10-09
CVE-2024-39525 [HIGH] CWE-755 CVE-2024-39525: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet wil
nvd
CVE-2021-31353P3HIGHCVSS 7.5≥ unspecified, < 20.4R2-S3-EVO, 20.4R3-EVO≥ 21.1-EVO, < 21.1R2-EVO+1 more2021-10-19
CVE-2021-31353 [HIGH] CWE-755 CVE-2021-31353: An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos
An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued receipt and processing of the BGP update will create a sustained Denial of Serv
nvd
CVE-2022-22197P3HIGHCVSS 7.5≥ unspecified, < 20.1R3-EVO≥ 20.2, < 20.2R3-EVO+1 more2022-04-14
CVE-2022-22197 [HIGH] CWE-672 CVE-2022-22197: An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon
An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an established BGP session to cause a Denial of Service (DoS). This issue occurs when proxy-generate route-target filtering is enabled, and cert
nvd
CVE-2022-22194P3HIGHCVSS 7.5≥ unspecified, < 20.4R2-S3-EVO, 20.4R3-EVO2022-04-14
CVE-2022-22194 [HIGH] CWE-754 CVE-2022-22194: An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juni
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos OS Evolved on PTX10003, PTX10004, and PTX10008 allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Continued receipt of these crafted packets will cause a sustained Denial of Service condition. This i
nvd
CVE-2023-22393P3HIGHCVSS 7.5≥ 21.4-EVO, < 21.4R2-S2-EVO, 21.4R3-EVO≥ 22.1-EVO, < 22.1R1-S2-EVO, 22.1R2-EVO+1 more2023-01-13
CVE-2023-22393 [HIGH] CWE-358 CVE-2023-22393: An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Jun
An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with invalid next-hop resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create
nvd
CVE-2024-39555P3HIGHCVSS 7.5fixed in 21.4R3-S8-EVO≥ 22.2-EVO, < 22.2R3-S4-EVO+4 more2024-07-10
CVE-2024-39555 [HIGH] CWE-755 CVE-2024-39555: An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Continued receipt and processing of these malformed BGP update mess
nvd
CVE-2024-39549P3HIGHCVSS 7.5fixed in 22.4R3-S5-EVO≥ 23.2-EVO, < 23.2R2-S3-EVO+2 more2024-07-11
CVE-2024-39549 [HIGH] CWE-401 CVE-2024-39549: A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rp
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial
nvd
CVE-2020-1662P3HIGHCVSS 7.5v19.4-EVO≥ 20.1-EVO, < 20.1R2-EVO2020-10-16
CVE-2020-1662 [HIGH] CWE-20 CVE-2020-1662: On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routin
On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limiting the attack surface to configured BGP peers. This issue only affects devices with BGP damping in combination with accepted-prefix-limit configuration. When the issue occurs the following messages will appea
nvd
CVE-2020-1638P3HIGHCVSS 7.5v19.2-EVOv19.3-EVO 19.2-EVO+1 more2020-04-08
CVE-2020-1638 [HIGH] CWE-467 CVE-2020-1638: The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart af
The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart after processing a specific IPv4 packet. Only packets destined to the device itself, successfully reaching the RE through existing edge and control plane filtering, will be able to cause the FPC restart. When this issue occurs, all traffic via the FPC will
nvd
CVE-2020-1648P3HIGHCVSS 7.5≥ 20.1-EVO, < 20.1R2-EVO2020-07-17
CVE-2020-1648 [HIGH] CWE-159 CVE-2020-1648: On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affec
nvd