VendorsJuniperex2200-vcall versions
Vulnerabilities

Juniper EX2200-VC

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2021-0289
Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted
Published 2021-07-15 · Modified
6.5EPSS 0.003
CVE-2018-0034
Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
Published 2018-07-11 · Modified
5.9EPSS 0.021
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.835
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562