Juniper Networks Junos OS Evolved vulnerabilities
246 known vulnerabilities affecting juniper_networks/junos_os_evolved.
Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145
Vulnerabilities
Page 7 of 13
CVE-2025-60006P4MEDIUMCVSS 5.3≥ 24.2, < 24.2R2-S2-EVO≥ 24.4, < 24.4R2-EVO2025-10-09
CVE-2025-60006 [MEDIUM] CWE-78 CVE-2025-60006: Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Comm
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands.
When an attacker executes crafted CLI commands, the options are processed via a script in some cas
nvd
CVE-2023-28973P4HIGHCVSS 7.1≥ unspecified, < 20.4R3-S5-EVO≥ 21.2, < 21.2R3-EVO+2 more2023-04-17
CVE-2023-28973 [HIGH] CWE-285 CVE-2023-28973: An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos O
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions such as daemon restarting, routing engine (RE) switchover, and node shutdo
nvd
CVE-2024-47495P4MEDIUMCVSS 6.7fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S8-EVO+5 more2024-10-11
CVE-2024-47495 [MEDIUM] CWE-639 CVE-2024-47495: An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated att
An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in use on Juniper Networks Junos OS Evolved devices.
This issue affects:
Juniper Networks Junos OS Evolved with dual-REs:
* All versions before 21.2R3-S8-E
nvd
CVE-2024-47491P4MEDIUMCVSS 5.9fixed in 21.4R3-S8-EVO≥ 22.2, < 22.2R3-S4-EVO+3 more2024-10-11
CVE-2024-47491 [MEDIUM] CWE-755 CVE-2024-47491: An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS).
When a BGP UPDATE with malformed path attribute is received over an established BGP session, rpd crashes and restarts.
nvd
CVE-2023-22402P4MEDIUMCVSS 5.9≥ 21.3, < 21.3R3-EVO≥ 21.4, < 21.4R2-EVO+2 more2023-01-13
CVE-2023-22402 [MEDIUM] CWE-416 CVE-2023-22402: A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthen
A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions
nvd
CVE-2025-60010P4MEDIUMCVSS 5.4fixed in 22.4R3-S8-EVO≥ 23.2, < 23.2R2-S4-EVO+3 more2025-10-09
CVE-2025-60010 [MEDIUM] CWE-262 CVE-2025-60010: A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolve
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change.
Affected devices allow logins by users for whom the RADIUS server has responded with a reject and required the user to change the p
nvd
CVE-2021-31360P4HIGHCVSS 7.1≥ unspecified, < 20.4R2-S3-EVO≥ 21.1R1-EVO, < 21.1*2021-10-19
CVE-2021-31360 [HIGH] CWE-20 CVE-2021-31360: An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved
An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending on the files overwritten, exploitation of this vulnerability could lead to a
nvd
CVE-2024-39538P4MEDIUMCVSS 6.5fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S7-EVO+5 more2024-07-11
CVE-2024-39538 [MEDIUM] CWE-120 CVE-2024-39538: A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand
A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated, adjacent attacker to cause a
Denial-of-Service (DoS).When multicast traffic with a specific, valid (S,G) is received, evo-pfemand crashes which leads to an outage of
nvd
CVE-2024-21618P4MEDIUMCVSS 6.5≥ 21.4-EVO, < 21.4R3-S5-EVO≥ 22.1-EVO, < 22.1R3-S4-EVO+4 more2024-04-12
CVE-2024-21618 [MEDIUM] CWE-788 CVE-2024-21618: An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daem
An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, when LLDP is enabled on a specific interface, and a malformed
nvd
CVE-2025-52964P4MEDIUMCVSS 6.5fixed in 21.4R3-S7-EVO≥ 22.3, < 22.3R3-S3-EVO+3 more2025-07-11
CVE-2025-52964 [MEDIUM] CWE-617 CVE-2025-52964: A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos O
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
When the device receives a specific BGP UPDATE packet, the rpd crashes and restarts. Continuous receipt of this specific packet will cause a
nvd
CVE-2026-33801P4MEDIUMCVSS 6.5≥ 25.2, < 25.2R2-EVO2026-07-09
CVE-2026-33801 [MEDIUM] CWE-754 CVE-2026-33801: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).
Upon receipt of a specifically malformed non-inet/
nvd
CVE-2022-22213P4MEDIUMCVSS 5.9≥ 21.1, < 21.1R3-S1-EVO≥ 21.2R1-EVO, < 21.2*+2 more2022-07-20
CVE-2022-22213 [MEDIUM] CWE-232 CVE-2022-22213: A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juni
A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juniper Networks Junos OS and Junos OS Evolved may allow an unauthenticated network-based attacker to crash the RPD process by sending a specific BGP update while the system is under heavy load, leading to a Denial of Service (DoS). Continued receipt and
nvd
CVE-2024-21585P4MEDIUMCVSS 5.9fixed in 21.3R3-S5-EVO≥ 21.4, < 21.4R3-S5-EVO+5 more2024-01-12
CVE-2024-21585 [MEDIUM] CWE-755 CVE-2024-21585: An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper N
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Den
nvd
CVE-2022-22219P4MEDIUMCVSS 5.9≥ 21.3R1-EVO, < 21.3*≥ 21.4, < 21.4R3-EVO+2 more2022-10-18
CVE-2022-22219 [MEDIUM] CWE-241 CVE-2022-22219: Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper
Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a specific EVPN route contained within a BGP Update, triggering a routing proto
nvd
CVE-2022-22220P4MEDIUMCVSS 5.9≥ unspecified, < 20.4R2-EVO≥ 21.1-EVO, < 21.1R2-EVO2022-10-18
CVE-2022-22220 [MEDIUM] CWE-367 CVE-2022-22220: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) o
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS). When a BGP flow route with redirect IP extended community is received, and the reachability to the next-hop of the corres
nvd
CVE-2022-22225P4MEDIUMCVSS 5.9≥ unspecified, < 20.4R3-S4-EVO≥ 21.1R1-EVO, < 21.1-EVO*+2 more2022-10-18
CVE-2022-22225 [MEDIUM] CWE-367 CVE-2022-22225: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rp
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker with an established BGP session to cause a Denial of Service (DoS). In a BGP multipath scenario, when one of the contributing routes is flapping often and rapidly,
nvd
CVE-2022-22208P4MEDIUMCVSS 5.9≥ unspecified, < 20.4R3-S4-EVO≥ 21.1-EVO, < 21.1R3-S2-EVO+2 more2022-10-18
CVE-2022-22208 [MEDIUM] CWE-416 CVE-2022-22208: A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and
A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service (DoS). When a BGP session flap happens, a Use After Free of a memory location that was assigned to another object can occur, which will lead to an rpd crash.
nvd
CVE-2025-52961P4MEDIUMCVSS 6.5≥ 23.2R1-EVO, < 23.2R2-S4-EVO≥ 23.4-EVO, < 23.4R2-S4-EVO+2 more2025-10-09
CVE-2025-52961 [MEDIUM] CWE-400 CVE-2025-52961: An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon
An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivity Fault Management Manager (cfmman) of Juniper Networks Junos OS Evolved on PTX10001-36MR, PTX10002-36QDD, PTX10004, PTX10008, PTX10016 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
An attacker o
nvd
CVE-2024-21590P4MEDIUMCVSS 6.5fixed in 21.2R3-S8-EVO≥ 21.4-EVO, < 21.4R3-S6-EVO+5 more2024-04-12
CVE-2024-21590 [MEDIUM] CWE-20 CVE-2024-21590: An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper
An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS Evolved allows an unauthenticated attacker within the MPLS administrative domain to send specifically crafted packets to the Routing Engine (RE) to cause a Denial of Service (DoS).
When specifically crafted transit MPLS IPv4 packets
nvd
CVE-2024-47498P4MEDIUMCVSS 6.5fixed in 21.4R3-S8-EVO≥ 22.2-EVO, < 22.2R3-S5-EVO+2 more2024-10-11
CVE-2024-47498 [MEDIUM] CVE-2024-47498: An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS
An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control pl
nvd