VendorsJuniperjunos19.2
Vulnerabilities

Juniper Junos 19.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

199CVEs
CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Published 2020-03-06 · Modified
10.0EPSS 0.743
CVE-2021-0249
Junos OS: SRX Series: A remote attacker may be able to cause a PFE buffer overflow to arbitrarily remotely execute code or commands on the target device with UTM enabled.
Published 2021-04-22 · Modified
10.0EPSS 0.018
CVE-2020-1615
Junos OS: vMX: Default credentials supplied in vMX configuration
Published 2020-04-08 · Modified
10.0EPSS 0.018
CVE-2020-1614
NFX250 Series: Hardcoded credentials in the vSRX VNF instance.
Published 2020-04-08 · Modified
10.0EPSS 0.014
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2020-1660
Junos OS: MX Series: Receipt of specific packets can cause services card to restart when DNS filtering is configured.
Published 2020-10-16 · Modified
9.9EPSS 0.008
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-05-04 · Analyzed
9.8KEVEPSS 0.048
CVE-2020-1647
Junos OS: SRX Series: Double free vulnerability can lead to DoS or remote code execution due to the processing of a specific HTTP message when ICAP redirect service is enabled
Published 2020-07-17 · Modified
9.8EPSS 0.026
CVE-2021-0254
Junos OS: Remote code execution vulnerability in overlayd service
Published 2021-04-22 · Modified
9.8EPSS 0.026
CVE-2020-1654
Junos OS: SRX Series: processing a malformed HTTP message when ICAP redirect service is enabled may can lead to flowd process crash or remote code execution
Published 2020-07-17 · Modified
9.8EPSS 0.022
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2022-22167
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy
Published 2022-01-19 · Modified
9.8EPSS 0.007
CVE-2021-0275
Junos OS: J-Web: Cross-site scripting attack allows an attacker to gain control of another users session.
Published 2021-04-22 · Modified
9.3EPSS 0.012
CVE-2021-0268
Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
Published 2021-04-22 · Modified
9.3EPSS 0.009
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2020-1673
Junos OS: Reflected Cross-site Scripting vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-10-16 · Modified
8.8EPSS 0.016
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2020-1656
Junos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.
Published 2020-10-16 · Modified
8.8EPSS 0.011
CVE-2020-1609
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.009
CVE-2021-0269
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
Published 2021-04-22 · Modified
8.8EPSS 0.009
CVE-2020-1605
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2020-1602
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets may take over the code execution of the JDHCPD process.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-0277
Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
Published 2021-07-15 · Modified
8.8EPSS 0.007
CVE-2021-0208
Junos OS and Junos OS Evolved: In bidirectional LSP configurations, on MPLS egress router RPD may core upon receipt of specific malformed RSVP packet.
Published 2021-01-15 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2020-1603
Junos OS: Improper handling of specific IPv6 packets sent by clients eventually kernel crash (vmcore) the device.
Published 2020-01-15 · Modified
8.6EPSS 0.014
CVE-2021-0251
Junos OS: MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC: The BRAS Subscriber Services service activation portal is vulnerable to a Denial of Service (DoS) via malformed HTTP packets
Published 2021-04-22 · Modified
8.6EPSS 0.011
CVE-2020-1632
Junos OS and Junos OS Evolved: Invalid BGP UPDATE sent to peer device may cause BGP session to terminate.
Published 2020-04-15 · Modified
8.6EPSS 0.011
CVE-2021-0203
Junos OS: EX and QFX5K Series: Storm Control does not work as expected when Redundant Trunk Group is configured
Published 2021-01-15 · Modified
8.6EPSS 0.010
CVE-2020-1667
Junos OS: MX Series: Services card might restart due to a race condition when DNS filtering is enabled.
Published 2020-10-16 · Modified
8.3EPSS 0.007
CVE-2020-1645
Junos OS: MX Series: Services card might restart when DNS filtering is enabled
Published 2020-07-17 · Modified
8.3EPSS 0.006
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2021-31373
Junos OS: SRX Series: Persistent XSS vulnerability in J-Web
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2022-22181
Junos OS: J-Web can be compromised through reflected XSS attacks
Published 2022-04-14 · Modified
8.0EPSS 0.007
CVE-2020-1686
Junos OS: Kernel crash (vmcore) upon receipt of a malformed IPv6 packet.
Published 2020-10-16 · Modified
7.8EPSS 0.014
1 / 5Next →