cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 5 of 13
CVE-2020-1644P3HIGHCVSS 7.5v19.2-EVOv19.3-EVO+2 more2020-07-17
CVE-2020-1644 [HIGH] CWE-703 CVE-2020-1644: On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE pack On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an internal counter to be incremented incorrectly, which over time can lead to the routing protocols process (RPD) crash and restart. This issue affects both IBGP and EBGP multihop deployment in IPv4 or IPv6 network. This issue affects: Juniper
nvd
CVE-2021-0250P3HIGHCVSS 7.5≥ 19.2-EVO, < 19.2R2-EVO2021-04-22
CVE-2021-0250 [HIGH] CVE-2021-0250: In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) f In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) feature is enable, a vulnerability in the Routing Protocol Daemon (RPD) process of Juniper Networks Junos OS allows an attacker to send a specific crafted BGP update message causing the RPD service to core, creating a Denial of Service (DoS) Condition. Continued r
nvd
CVE-2020-1646P3HIGHCVSS 7.5≥ unspecified, < 19.3R1-EVO≥ 19.2R2-EVO, < 19.2-EVO*2020-07-17
CVE-2020-1646 [HIGH] CWE-159 CVE-2020-1646: On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue occurs only when the device is receiving and processing the BGP UPDATE for an EBGP peer. This issue does not occur when the device is receiving and processing the BGP UPDATE for
nvd
CVE-2021-31374P3HIGHCVSS 7.5≥ 20.3, < 20.3R2-EVO2021-10-19
CVE-2021-31374 [HIGH] CWE-787 CVE-2021-31374: On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this message will create a sustained Denial of Service (DoS) condition. This issue affects both IBGP
nvd
CVE-2021-0264P3HIGHCVSS 7.5≥ unspecified, < 20.4R2-EVO2021-04-22
CVE-2021-0264 [HIGH] CWE-703 CVE-2021-0264: A vulnerability in the processing of traffic matching a firewall filter containing a syslog action i A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card to crash and restart, creating a Denial of Service (DoS). Continued receipt and processing of packets matching the fi
nvd
CVE-2021-0226P3HIGHCVSS 7.5≥ 19.4-EVO, < 19.4R2-S3-EVO≥ 20.1-EVO, < 20.1R2-S3-EVO+2 more2021-04-22
CVE-2021-0226 [HIGH] CWE-665 CVE-2021-0226: On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an establi On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue does not affect IPv4 BGP sessions. This issue affects I
nvd
CVE-2021-0281P3HIGHCVSS 7.5≥ All, < 20.4R2-S2-EVO2021-07-15
CVE-2021-0281 [HIGH] CWE-754 CVE-2021-0281: On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server may cause routing process daemon (RPD) to crash and restart, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustain
nvd
CVE-2022-22211P3HIGHCVSS 7.5≥ unspecified, < 20.4R3-S4-EVO≥ 21.1R1-EVO, < 21.1-EVO*+4 more2022-10-18
CVE-2022-22211 [HIGH] CWE-770 CVE-2022-22211: A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Continuously polling the SNMP jnxCosQstatTable causes the FPC to run out of GUID space, causing a Denial of Service to the FPC resources. When the FPC runs out of the GUID sp
nvd
CVE-2026-21908P3HIGHCVSS 7.1≥ 23.2R2-S1, < 23.2R2-S5-EVO≥ 23.4R2, < 23.4R2-S6-EVO+3 more2026-01-15
CVE-2026-21908 [HIGH] CWE-416 CVE-2026-21908: A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Junipe A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the proc
nvd
CVE-2025-59958P3MEDIUMCVSS 6.5fixed in 22.4R3-EVO≥ 23.2, < 23.2R2-EVO2025-10-09
CVE-2025-59958 [MEDIUM] CWE-754 CVE-2025-59958: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engin An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability. When an output firewall filter is configured with one or more terms where the action is
nvd
CVE-2021-0286P3HIGHCVSS 7.5≥ unspecified, < 20.4R2-EVO≥ 21.1, < 21.1R2-EVO2021-07-15
CVE-2021-0286 [HIGH] CWE-703 CVE-2021-0286: A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) allows an attacker to send specially crafted packets to the device, causing the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) process to crash and restart, impacting all traffic going through the FPC, resulting in a Denial of Ser
nvd
CVE-2026-33797P3HIGHCVSS 7.4≥ 25.2, < 25.2R2-EVO2026-04-09
CVE-2026-33797 [HIGH] CWE-20 CVE-2026-33797: An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet will sustain the Denial of Service
nvd
CVE-2024-39553P3MEDIUMCVSS 6.5≥ 21.4-EVO, < 21.4R3-S7-EVO≥ 22.2-EVO, < 22.2R3-S3-EVO+3 more2024-07-11
CVE-2024-39553 [MEDIUM] CWE-668 CVE-2024-39553: An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Ju An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send arbitrary data to the device, which leads msvcsd process to crash with limited availability impacting Denial of Service (DoS) and allows unauthorized network access to the device,
nvd
CVE-2026-33803P3MEDIUMCVSS 6.5fixed in 23.2R2-S7-EVO≥ 23.4, < 23.4R2-S8-EVO+4 more2026-07-09
CVE-2026-33803 [MEDIUM] CWE-923 CVE-2026-33803: An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Netw An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, a process which should only be able to communicate internally wit
nvd
CVE-2020-1626P3HIGHCVSS 7.5≥ unspecified, < 19.1R1-EVO2020-04-08
CVE-2020-1626 [HIGH] CVE-2020-1626: A vulnerability in Juniper Networks Junos OS Evolved may allow an attacker to cause a Denial of Serv A vulnerability in Juniper Networks Junos OS Evolved may allow an attacker to cause a Denial of Service (DoS) by sending a high rate of specific packets to the device, resulting in a pfemand process crash. The pfemand process is responsible for packet forwarding on the device. By continuously sending the packet flood, an attacker can repeatedly crash the pfeman
nvd
CVE-2025-59960P3HIGHCVSS 7.4fixed in 21.4R3-S12-EVO≥ 22.2, < 22.2*+6 more2026-01-15
CVE-2025-59960 [HIGH] CWE-754 CVE-2025-59960: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (j An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server. By default, the DHCP relay agent inserts its
nvd
CVE-2024-39546P3HIGHCVSS 7.3fixed in 21.2R3-S8-EVO≥ 21.4, < 21.4R3-S6-EVO+5 more2024-07-11
CVE-2024-39546 [HIGH] CWE-862 CVE-2024-39546: A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system. Thi
nvd
CVE-2022-22248P3HIGHCVSS 7.3≥ 20.4-EVO, < 20.4R3-S1-EVO≥ 21.1R1-EVO, < 21.1-EVO*+2 more2022-10-18
CVE-2022-22248 [HIGH] CWE-732 CVE-2022-22248: An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Ev An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modify the contents of a configuration file which could cause another user to execute arbitrary commands within the context of the follow-on user's session. If the follow-on user is a high-privileged administr
nvd
CVE-2026-33791P3MEDIUMCVSS 6.7fixed in 22.4R3-S8-EVO≥ 23.2, < 23.2R2-S5-EVO+4 more2026-04-09
CVE-2026-33791 [MEDIUM] CWE-78 CVE-2026-33791: An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos O An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Certain 'set system' commands, when executed with crafted arguments
nvd
CVE-2026-21921P3MEDIUMCVSS 6.5fixed in 22.4R3-S8-EVO≥ 23.2, < 23.2R2-S5-EVO+1 more2026-01-15
CVE-2026-21921 [MEDIUM] CWE-416 CVE-2026-21921: A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Jun A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-c
nvd
Juniper Networks Junos OS Evolved vulnerabilities | cvebase