Juniper Networks Junos OS Evolved vulnerabilities
246 known vulnerabilities affecting juniper_networks/junos_os_evolved.
Total CVEs
246
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH99MEDIUM145
Vulnerabilities
Page 9 of 13
CVE-2023-22406P4MEDIUMCVSS 6.5≥ unspecified, < 20.4R3-S4-EVO≥ 21.4, < 21.4R2-S1-EVO, 21.4R3-EVO+1 more2023-01-13
CVE-2023-22406 [MEDIUM] CWE-401 CVE-2023-22406: A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). In a segment-routing scenario with OSPF as IGP, when a peer interface continuously flaps, next-hop churn will happen and a continuous incre
nvd
CVE-2023-36849P4MEDIUMCVSS 6.5≥ 21.4, < 21.4R3-S2-EVO≥ 22.1, < 22.1R3-S3-EVO+2 more2023-07-14
CVE-2023-36849 [MEDIUM] CWE-703 CVE-2023-36849: An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protoco
An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS).
When a malformed LLDP packet is received, l2cpd will crash and restart. The impact of the l2cpd crash
nvd
CVE-2023-28981P4MEDIUMCVSS 6.5≥ 20.3R1-EVO, < 20.3-EVO*≥ 20.4-EVO, < 20.4R3-S6-EVO+3 more2023-04-17
CVE-2023-28981 [MEDIUM] CWE-20 CVE-2023-28981: An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS E
An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If the receipt of router advertisements is enabled on an interface and a specifically malformed RA packet is received, memory corruption will happen which leads to
nvd
CVE-2022-22250P4MEDIUMCVSS 6.5≥ unspecified, < 20.4R3-S3-EVO≥ 21.1R1-EVO, < 21.1-EVO*+3 more2022-10-18
CVE-2022-22250 [MEDIUM] CWE-664 CVE-2022-22250: An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PF
An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned locally on an access interface but later a request to delete is received indi
nvd
CVE-2025-52953P4MEDIUMCVSS 6.5fixed in 22.2R3-S7-EVO≥ 22.4-EVO, < 22.4R3-S7-EVO+4 more2025-07-11
CVE-2025-52953 [MEDIUM] CWE-440 CVE-2025-52953: An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Network
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denial of Service (DoS).
Continuous receipt and processing of this packet will create a sustain
nvd
CVE-2023-36839P4MEDIUMCVSS 6.5fixed in 20.4R3-S8-EVO≥ 21.1R1-EVO, < 21.1*-EVO+7 more2023-10-12
CVE-2023-36839 [MEDIUM] CWE-1284 CVE-2023-36839: An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocol
An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial of Service(DoS).
This issue occurs when specific LLDP packets are received and telemetry p
nvd
CVE-2025-52949P4MEDIUMCVSS 6.5fixed in 22.2R3-S7-EVO≥ 22.4-EVO, < 22.4R3-S7-EVO+4 more2025-07-11
CVE-2025-52949 [MEDIUM] CWE-130 CVE-2025-52949: An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this
nvd
CVE-2024-39558P4MEDIUMCVSS 6.5fixed in 20.4R3-S10-EVO≥ 21.2R1-EVO, < 21.2*-EVO+5 more2024-07-10
CVE-2024-39558 [MEDIUM] CWE-252 CVE-2024-39558: An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Jun
An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically adjacent, unauthenticated attacker sending a specific PIM packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS), when PIM is configured with Multicast-only Fast
nvd
CVE-2025-30653P4MEDIUMCVSS 6.5fixed in 22.2R3-S4-EVO≥ 22.4-EVO, < 22.4R3-S2-EVO+2 more2025-04-09
CVE-2025-30653 [MEDIUM] CWE-825 CVE-2025-30653: An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Ju
An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).On all Junos OS and Junos OS Evolved platforms, when an MPLS Label-Switched Path (LSP) is configured with node-link-protection and transport-clas
nvd
CVE-2025-30646P4MEDIUMCVSS 6.5fixed in 21.4R3-S10-EVO≥ 22.2-EVO, < 22.2R3-S6-EVO+4 more2025-04-09
CVE-2025-30646 [MEDIUM] CWE-195 CVE-2025-30646: A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) o
A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS). Continued recei
nvd
CVE-2025-21602P4MEDIUMCVSS 6.5≥ 21.4, < 21.4R3-S9-EVO≥ 22.2, < 22.2R3-S5-EVO+5 more2025-01-09
CVE-2025-21602 [MEDIUM] CWE-755 CVE-2025-21602: An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS).
Continuous receipt and processing of this pack
nvd
CVE-2026-21911P4MEDIUMCVSS 6.5fixed in 21.4R3-S7-EVO≥ 22.2, < 22.2R3-S4-EVO+4 more2026-01-15
CVE-2026-21911 [MEDIUM] CWE-682 CVE-2026-21911: An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper
An Incorrect Calculation vulnerability in the Layer 2 Control
Protocol
Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of new MACs over label-switched interfaces (LSI) to stop while generating a flood of logs, resulting in high CPU usage.
W
nvd
CVE-2026-33780P4MEDIUMCVSS 6.5≥ all version prior to, < 22.4R3-S5-EVO≥ 23.2, < 23.2R2-S3-EVO+2 more2026-04-09
CVE-2026-33780 [MEDIUM] CWE-401 CVE-2026-33780: A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning D
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).
In an EVPN-MPLS scenario, routes learned from remote multi-homed Pro
nvd
CVE-2021-0225P4MEDIUMCVSS 5.8≥ 19.1R1-EVO, < unspecified≥ 20.3-EVO, < 20.3R1-S2-EVO, 20.3R2-EVO2021-04-22
CVE-2021-0225 [MEDIUM] CWE-754 CVE-2021-0225: An Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS Evolved may cau
An Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS Evolved may cause the stateless firewall filter configuration which uses the action 'policer' in certain combinations with other options to not take effect. An administrator can use the following CLI command to see the failures with filter configuration: user@device>
nvd
CVE-2024-21596P4MEDIUMCVSS 5.3fixed in 21.3R3-S5-EVO≥ 21.4-EVO, < 21.4R3-S5-EVO+5 more2024-01-12
CVE-2024-21596 [MEDIUM] CWE-122 CVE-2024-21596: A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).
If an attacker sends a specific BGP UPDATE message to the device, this will cause a memory overwrite and therefore an RPD crash and res
nvd
CVE-2024-30409P4MEDIUMCVSS 5.3≥ 22.1-EVO, < 22.1R1-S2-EVO, 22.1R2-EVO2024-04-12
CVE-2024-30409 [MEDIUM] CWE-754 CVE-2024-30409: An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Jun
An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to crash, leading to a limited Denial of Service.
This issue affects Juniper Networks
Junos O
nvd
CVE-2024-39512P4MEDIUMCVSS 6.6≥ 23.2R2-EVO, < 23.2R2-S1-EVO≥ 23.4R1-EVO, < 23.4R2-EVO2024-07-10
CVE-2024-39512 [MEDIUM] CWE-1263 CVE-2024-39512: An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Ju
An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the device to get access to a user account.
When the console cable is disconnected, the logged in user is not logged out. This allows a malicious attacker with physical access to the console
nvd
CVE-2021-0209P4MEDIUMCVSS 6.5≥ 19.4, < 19.4R2-S2-EVO≥ 20.1, < 20.1R1-S2-EVO, 20.1R2-S1-EVO2021-01-15
CVE-2021-0209 [MEDIUM] CWE-824 CVE-2021-0209: In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause
In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to access an uninitialized pointer causing RPD to core leading to a Denial of Service (DoS). Continued receipt of these types of valid BGP update packets will cause an extended Denial of Service condition. RPD will require a restart to r
nvd
CVE-2021-31362P4MEDIUMCVSS 6.5≥ unspecified, < 20.4R2-EVO≥ 21.1, < 21.1R2-EVO2021-10-19
CVE-2021-31362 [MEDIUM] CWE-693 CVE-2021-31362: A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Ju
A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading to a Denial of Service (DoS) condition. Continued receipted of these spoofed PDUs will cre
nvd
CVE-2021-31363P4MEDIUMCVSS 6.5≥ unspecified, < 20.1R2-S3-EVO≥ 20.3, < 20.3R1-S2-EVO2021-10-19
CVE-2021-31363 [MEDIUM] CWE-835 CVE-2021-31363: In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing prot
In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause high load on RPD which in turn may lead to routing protocol flaps. If a system with sensor-based-stats enabled receives a specific
nvd