VendorsJuniperex9200any version
Vulnerabilities

Juniper EX9200 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2021-0275
Junos OS: J-Web: Cross-site scripting attack allows an attacker to gain control of another users session.
Published 2021-04-22 · Modified
9.3EPSS 0.012
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2018-0005
Security Bulletin: Junos OS: MAC move limit configured to drop traffic may forward traffic.
Published 2018-01-10 · Modified
8.8EPSS 0.007
CVE-2020-1613
Junos OS: BGP session termination upon receipt of specific BGP FlowSpec advertisement.
Published 2020-04-08 · Modified
8.6EPSS 0.013
CVE-2025-30650
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
Published 2026-04-08 · Analyzed
8.4EPSS 0.001
CVE-2018-0024
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Published 2018-07-11 · Modified
7.8EPSS 0.004
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
CVE-2021-0202
Junos OS: MX Series, EX9200 Series: Trio-based MPC memory leak when Integrated Routing and Bridging (IRB) interface is mapped to a VPLS instance or a Bridge-Domain
Published 2021-01-15 · Modified
7.5EPSS 0.010
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2020-1607
Junos OS: Cross-Site Scripting (XSS) in J-Web
Published 2020-01-15 · Modified
7.5EPSS 0.009
CVE-2023-44191
Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2021-0217
Junos OS: EX Series and QFX Series: Memory leak issue processing specific DHCP packets
Published 2021-01-15 · Modified
7.4EPSS 0.007
CVE-2021-0244
Junos OS: A race condition in the storm control profile may allow an attacker to cause a Denial of Service condition
Published 2021-04-22 · Modified
7.4EPSS 0.006
CVE-2018-0008
Junos OS: commit script may allow unauthenticated root login upon reboot
Published 2018-01-10 · Modified
7.2EPSS 0.005
CVE-2024-39526
Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11/LC9600, MX304, EX9200, PTX Series: Receipt of malformed DHCP packets causes interfaces to stop processing packets
Published 2024-10-11 · Analyzed
7.1EPSS 0.004
CVE-2024-47501
Junos OS: MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C: In a VPLS or Junos Fusion scenario specific show commands cause FPCs to crash
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2021-0257
Junos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interface
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0288
Junos OS: MX Series, EX9200 Series: FPC may crash upon receipt of specific MPLS packet affecting Trio-based MPCs
Published 2021-07-15 · Modified
6.5EPSS 0.004
CVE-2021-0290
Junos OS: MX Series, EX9200 Series, SRX4600: Ethernet interface vulnerable to specially crafted frames
Published 2021-07-15 · Modified
6.5EPSS 0.004
CVE-2021-0289
Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted
Published 2021-07-15 · Modified
6.5EPSS 0.003
CVE-2018-0034
Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
Published 2018-07-11 · Modified
5.9EPSS 0.021
CVE-2019-0074
Junos OS: NFX150 Series, QFX10K Series, EX9200 Series, MX Series, PTX Series: Path traversal vulnerability in NFX150 and NG-RE leads to information disclosure.
Published 2019-10-09 · Modified
5.5EPSS 0.004
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.854
CVE-2020-1665
Junos OS: MX series/EX9200 Series: IPv6 DDoS protection does not work as expected.
Published 2020-10-16 · Modified
5.3EPSS 0.013
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2021-0273
Junos OS and Junos OS Evolved: Trio Chipset: Denial of Service due to packet destined to device's interfaces.
Published 2021-04-22 · Modified
5.3EPSS 0.010
CVE-2020-1661
Junos OS: jdhcpd process crash when forwarding a malformed DHCP packet.
Published 2020-10-16 · Modified
5.3EPSS 0.010
CVE-2024-21607
Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected
Published 2024-01-12 · Modified
5.3EPSS 0.003
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562