VendorsJuniperex4400all versions
Vulnerabilities

Juniper EX4400

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2021-0275
Junos OS: J-Web: Cross-site scripting attack allows an attacker to gain control of another users session.
Published 2021-04-22 · Modified
9.3EPSS 0.012
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2024-39565
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
Published 2024-07-10 · Analyzed
8.8EPSS 0.005
CVE-2024-47497
Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2025-30644
Junos OS: EX2300, EX3400, EX4000 Series, QFX5k Series: Receipt of a specific DHCP packet causes FPC crash when DHCP Option 82 is enabled
Published 2025-04-09 · Analyzed
7.7EPSS 0.003
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
CVE-2021-0285
Junos OS: QFX5000 Series and EX4600 Series: Continuous traffic destined to a device configured with MC-LAG leading to nodes losing their control connection which can impact traffic
Published 2021-07-15 · Modified
7.5EPSS 0.010
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2024-21595
Junos OS: EX4100, EX4400, EX4600, QFX5000 Series: A high rate of specific ICMP traffic will cause the PFE to hang
Published 2024-01-12 · Modified
7.5EPSS 0.005
CVE-2023-44191
Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2021-0244
Junos OS: A race condition in the storm control profile may allow an attacker to cause a Denial of Service condition
Published 2021-04-22 · Modified
7.4EPSS 0.006
CVE-2026-57032
Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash
Published 2026-07-09 · Analyzed
7.1EPSS 0.004
CVE-2024-30388
Junos OS: QFX5000 Series and EX Series: Specific malformed LACP packets will cause flaps
Published 2024-04-12 · Analyzed
7.1EPSS 0.003
CVE-2026-21910
Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop
Published 2026-01-15 · Analyzed
7.1EPSS 0.003
CVE-2026-33781
Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed
Published 2026-04-09 · Analyzed
7.1EPSS 0.003
CVE-2026-57027
Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash
Published 2026-07-09 · Analyzed
7.1EPSS 0.003
CVE-2026-33773
Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physical interface one of those is not applied
Published 2026-04-09 · Analyzed
6.9EPSS 0.003
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
Published 2026-01-15 · Modified
6.8EPSS 0.001
CVE-2026-57025
Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
Published 2026-07-09 · Modified
6.8EPSS 0.001
CVE-2026-33802
Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
Published 2026-07-09 · Analyzed
6.8EPSS 0.001
CVE-2023-44203
Junos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2021-0289
Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted
Published 2021-07-15 · Modified
6.5EPSS 0.003
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.835
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562