VendorsJuniperjunos23.4
Vulnerabilities

Juniper Junos 23.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

120CVEs
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2024-39565
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
Published 2024-07-10 · Analyzed
8.8EPSS 0.005
CVE-2024-47499
Junos OS and Junos OS Evolved: In a BMP scenario receipt of a malformed AS PATH attribute can cause an RPD crash
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2024-47504
Junos OS: SRX5000 Series: Receipt of a specific malformed packet will cause a flowd crash
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2024-47497
Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2026-33782
Junos OS: MX Series: In specific DHCPv6 scenarios jdhcpd memory increases continuously with subscriber logouts
Published 2026-04-09 · Analyzed
8.7EPSS 0.006
CVE-2026-21906
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.006
CVE-2024-39555
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset
Published 2024-07-10 · Analyzed
8.7EPSS 0.005
CVE-2026-21920
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.005
CVE-2024-39549
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2026-33790
Junos OS: SRX Series: In a NAT64 configuration, receipt of a specific, malformed ICMPv6 packet will cause the srxpfe process to crash and restart.
Published 2026-04-09 · Analyzed
8.7EPSS 0.005
CVE-2026-33778
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
Published 2026-04-09 · Analyzed
8.7EPSS 0.005
CVE-2026-57023
Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2026-57026
Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2024-39515
Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.005
CVE-2025-52980
Junos OS: SRX300 Series: rpd will crash upon receiving a specific, valid BGP UPDATE message
Published 2025-07-11 · Analyzed
8.7EPSS 0.005
CVE-2025-52946
Junos OS and Junos OS Evolved: With traceoptions enabled, receipt of malformed AS PATH causes RPD crash
Published 2025-07-11 · Analyzed
8.7EPSS 0.004
CVE-2025-52981
Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash
Published 2025-07-11 · Analyzed
8.7EPSS 0.004
CVE-2024-39516
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.004
CVE-2024-39525
Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.004
CVE-2025-60004
Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash
Published 2025-10-09 · Analyzed
8.7EPSS 0.004
CVE-2024-39564
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2025-21601
Junos OS: SRX and EX Series, MX240, MX480, MX960, QFX5120 Series: When web management is enabled for specific services an attacker may cause a CPU spike by sending genuine packets to the device
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-60003
Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2025-30645
Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21905
Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2025-30656
Junos OS: MX Series, SRX Series: Processing of specific SIP INVITE messages by the SIP ALG will lead to an FPC crash
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30649
Junos OS: MX240, MX480, MX960 with SPC3: An attacker sending specific packets will cause a CPU utilization DoS.
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21917
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2025-30660
Junos OS: MX Series: Decapsulation of specific GRE packets leads to PFE reset
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30658
Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30659
Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30651
Junos OS and Junos OS Evolved: Receipt of a specific ICMPv6 packet causes a memory overrun leading to an rpd crash
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-21594
Junos OS: MX Series: In DS-lite and NAT scenario receipt of crafted IPv6 traffic causes port block
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21918
Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-21914
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.003
CVE-2025-52983
Junos OS: After removing ssh public key authentication root can still log in
Published 2025-07-11 · Analyzed
8.6EPSS 0.006
CVE-2025-30661
Junos OS: Low-privileged user can cause script to run as root, leading to privilege escalation
Published 2025-07-11 · Analyzed
8.5EPSS 0.002
CVE-2026-33793
Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system
Published 2026-04-09 · Analyzed
8.5EPSS 0.002
CVE-2026-33791
Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root
Published 2026-04-09 · Modified
8.4EPSS 0.007
1 / 3Next →