cbcvebase.

Juniper Networks Junos OS Evolved vulnerabilities

246 known vulnerabilities affecting juniper_networks/junos_os_evolved.

Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145

Vulnerabilities

Page 6 of 13
CVE-2026-21919P3MEDIUMCVSS 6.5≥ 23.4, < 23.4R2-S5-EVO≥ 24.2, < 24.2R2-S1-EVO+1 more2026-04-09
CVE-2026-21919 [MEDIUM] CWE-821 CVE-2026-21919: An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane. When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to ha
nvd
CVE-2023-28960P3HIGHCVSS 8.2≥ 20.4, < 20.4R3-S5-EVO≥ 21.2, < 21.2R3-EVO+2 more2023-04-17
CVE-2023-28960 [HIGH] CWE-732 CVE-2023-28960: An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a local, authenticated low-privileged attacker to copy potentially malicious files into an existing Docker container on the local system. A follow-on administrator could then inadvertently start the Docker container leading to the maliciou
nvd
CVE-2025-30648P3HIGHCVSS 7.4≥ 22.4, < 22.4R3-S6-EVO≥ 23.2, < 23.2R2-S3-EVO+2 more2025-04-09
CVE-2025-30648 [HIGH] CWE-20 CVE-2025-30648: An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks J An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS). When a specifically malformed DHCP packet is received from a DHCP client, the jdhcpd process crashes,
nvd
CVE-2023-44184P3MEDIUMCVSS 6.5fixed in 21.4R3-S4-EVO≥ 22.1, < 22.1R3-S2-EVO+3 more2023-10-13
CVE-2023-44184 [MEDIUM] CWE-119 CVE-2023-44184: An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the man An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a specific command via NETCONF, to cause a CPU Denial of Service to the device's control plane. Th
nvd
CVE-2024-39537P3MEDIUMCVSS 6.5fixed in 21.4R3-S7-EVO≥ 22.2-EVO, < 22.2R3-S4-EVO+4 more2024-07-11
CVE-2024-39537 [MEDIUM] CWE-923 CVE-2024-39537: An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Netw An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, specific processes which should only be able t
nvd
CVE-2026-33783P3MEDIUMCVSS 6.5fixed in 22.4R3-S9-EVO≥ 23.2, < 23.2R2-S6-EVO+4 more2026-04-09
CVE-2026-33783 [MEDIUM] CWE-686 CVE-2026-33783: A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networ A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used to monitor traffic in these t
nvd
CVE-2021-0297P3MEDIUMCVSS 6.5≥ unspecified, < 20.3R2-S1-EVO≥ 20.4, < 20.4R2-EVO+1 more2021-10-19
CVE-2021-0297 [MEDIUM] CWE-755 CVE-2021-0297: A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to untrusted or unauthorized sessions being established, resulting in an impact on confidentiality
nvd
CVE-2021-0291P3MEDIUMCVSS 6.5≥ unspecified, < 20.3R2-EVO2021-07-15
CVE-2021-0291 [MEDIUM] CWE-497 CVE-2021-0291: An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traffic which partially reaches this resource. A high rate of specific traffic may lead to a partial Denial of Service (
nvd
CVE-2025-52988P3MEDIUMCVSS 6.7fixed in 22.4R3-S6-EVO≥ 23.2-EVO, < 23.2R2-S1-EVO+1 more2025-07-11
CVE-2025-52988 [MEDIUM] CWE-78 CVE-2025-52988: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root. When a user provides specifically crafted arguments to the 'request system logout' command, these will
nvd
CVE-2024-47505P3MEDIUMCVSS 6.5≥ 21.4, < 21.4R2-EVO≥ 22.1, < 22.1R2-EVO2024-10-11
CVE-2024-47505 [MEDIUM] CWE-770 CVE-2024-47505: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon ( An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operations or specific low-priviledged CLI commands are executed, a GUI
nvd
CVE-2021-0259P3HIGHCVSS 7.4≥ unspecified, < 20.3R2-EVO2021-04-22
CVE-2021-0259 [HIGH] CWE-755 CVE-2021-0259: Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the overlay network sends a high volume
nvd
CVE-2025-60011P3MEDIUMCVSS 5.8fixed in 22.4R3-S8-EVO≥ 23.2, < 23.2R2-S5-EVO+3 more2026-01-15
CVE-2025-60011 [MEDIUM] CWE-754 CVE-2025-60011: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an affected device receives a specific optional, transitive BGP attribute over an
nvd
CVE-2024-39556P4HIGHCVSS 7.0fixed in 21.4R3-S7-EVO≥ 22.1-EVO, < 22.1R3-S6-EVO+5 more2024-07-10
CVE-2024-39556 [HIGH] CWE-121 CVE-2024-39556: A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution. By exploiting the 'set security certificates' comma
nvd
CVE-2021-0236P4MEDIUMCVSS 6.5≥ 20.3-EVO, < 20.3R2-EVO2021-04-22
CVE-2021-0236 [MEDIUM] CWE-754 CVE-2021-0236: Due to an improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Juno Due to an improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved the Routing Protocol Daemon (RPD) service, upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, crashes and restarts causing a Denial of Service (DoS). Continued receipt and processing of thi
nvd
CVE-2026-33794P3MEDIUMCVSS 5.9≥ 24.4R2-EVO, < 24.4R2-S3-EVO≥ 25.2, < 25.2R2, 25.2R2-EVO2026-07-09
CVE-2026-33794 [MEDIUM] CWE-754 CVE-2026-33794: An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding t An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a
nvd
CVE-2024-47489P4MEDIUMCVSS 5.8fixed in 21.4R3-S8-EVO≥ 22.2, < 22.2R3-S4-EVO+5 more2024-10-11
CVE-2024-47489 [MEDIUM] CWE-755 CVE-2024-47489: An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) o An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices. Receipt of specific transit pr
nvd
CVE-2024-39559P4MEDIUMCVSS 5.9fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S6-EVO+4 more2024-07-10
CVE-2024-39559 [MEDIUM] CWE-754 CVE-2024-39559: An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Junipe An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to crash the device (vmcore) by sending a specific TCP packet over an established TCP session with MD5 authentication enabled, destined to an accessible port on the device,
nvd
CVE-2025-52984P3MEDIUMCVSS 5.9fixed in 22.4R3-S7-EVO≥ 23.2-EVO, < 23.2R2-S3-EVO+2 more2025-07-11
CVE-2025-52984 [MEDIUM] CWE-476 CVE-2025-52984: A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device. When static route points to a reject next hop and a gNMI query is processed for that static route, rpd crashes and restar
nvd
CVE-2024-39554P3MEDIUMCVSS 5.9≥ 21.1-EVO, < 21.1*-EVO≥ 21.2-EVO, < 21.2*-EVO+6 more2024-07-10
CVE-2024-39554 [MEDIUM] CWE-362 CVE-2024-39554: A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulner A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash
nvd
CVE-2024-47507P3MEDIUMCVSS 5.8fixed in 21.4R3-S7-EVO≥ 22.2, < 22.2R3-S4-EVO+1 more2024-10-11
CVE-2024-47507 [MEDIUM] CWE-754 CVE-2024-47507: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices. When a peer sends a BGP update message which contains the aggregator attribute with an
nvd
Juniper Networks Junos OS Evolved vulnerabilities | cvebase