VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2026-21908
Junos OS and Junos OS Evolved: Use after free vulnerability In 802.1X authentication daemon can cause crash of the dot1xd process
Published 2026-01-15 · Analyzed
7.5EPSS 0.003
CVE-2021-0217
Junos OS: EX Series and QFX Series: Memory leak issue processing specific DHCP packets
Published 2021-01-15 · Modified
7.4EPSS 0.007
CVE-2021-0222
Junos OS: Upon receipt of certain protocol packets with invalid payloads a self-propagating Denial of Service may occur.
Published 2021-01-15 · Modified
7.4EPSS 0.006
CVE-2021-0244
Junos OS: A race condition in the storm control profile may allow an attacker to cause a Denial of Service condition
Published 2021-04-22 · Modified
7.4EPSS 0.006
CVE-2019-0054
Junos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.
Published 2019-10-09 · Modified
7.4EPSS 0.006
CVE-2017-10620
SRX Series: Antivirus updates are downloaded without verification
Published 2017-10-13 · Modified
7.4EPSS 0.006
CVE-2022-22156
Junos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URL
Published 2022-01-19 · Modified
7.4EPSS 0.006
CVE-2020-1633
Junos OS: MX Series: Crafted packets traversing a Broadband Network Gateway (BNG) configured with IPv6 NDP proxy could lead to Denial of Service
Published 2020-04-09 · Modified
7.4EPSS 0.005
CVE-2021-0267
Junos OS: Receipt of a crafted DHCP packet will cause the jdhcpd DHCP service to core.
Published 2021-04-22 · Modified
7.4EPSS 0.005
CVE-2021-0241
Junos OS: Receipt of specific DHCPv6 packet may cause jdhcpd to crash and restart
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2021-0240
Junos OS: Receipt of malformed DHCPv6 packets causes jdhcpd to crash and restart.
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2021-0259
Junos OS and Junos OS Evolved: QFX5K Series: Underlay network traffic might not be processed upon receipt of high rate of specific genuine overlay packets in VXLAN scenario
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2022-22163
Junos OS: jdhcpd crashes upon receipt of a specific DHCPv6 packet
Published 2022-01-19 · Modified
7.4EPSS 0.004
CVE-2022-22176
Junos OS: In a scenario with dhcp-security and option-82 configured jdhcpd crashes upon receipt of a malformed DHCP packet
Published 2022-01-19 · Modified
7.4EPSS 0.004
CVE-2025-21591
Junos OS: An unauthenticated adjacent attacker sending a malformed DHCP packet causes jdhcpd to crash
Published 2025-04-09 · Analyzed
7.4EPSS 0.003
CVE-2023-28974
Junos OS: MX Series: In a BBE scenario upon receipt of specific malformed packets from subscribers the process bbe-smgd will crash
Published 2023-04-17 · Modified
7.4EPSS 0.003
CVE-2026-33797
Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset
Published 2026-04-09 · Modified
7.4EPSS 0.003
CVE-2025-59960
Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP server
Published 2026-01-15 · Analyzed
7.4EPSS 0.003
CVE-2025-30648
Junos OS and Junos OS Evolved: Receipt of a specifically malformed DHCP packet causes jdhcpd process to crash
Published 2025-04-09 · Analyzed
7.4EPSS 0.002
CVE-2021-0235
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series: In a multi-tenant environment, a tenant host administrator may configure logical firewall isolation affecting other tenant networks
Published 2021-04-22 · Modified
7.3EPSS 0.002
CVE-2021-0246
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3: In a multi-tenant environment, a tenant host administrator may be able to jailbreak out of their network impacting other tenant networks or gather information from other networks.
Published 2021-04-22 · Modified
7.3EPSS 0.002
CVE-2026-21916
Junos OS: A low privileged user can escalate their privileges so that they can login as root
Published 2026-04-09 · Analyzed
7.3EPSS 0.001
CVE-2020-1637
Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
Published 2020-04-08 · Modified
7.2EPSS 0.008
CVE-2021-31375
Junos OS: Receipt of a specific BGP update may cause RPKI policy-checks to be bypassed
Published 2021-10-19 · Modified
7.2EPSS 0.008
CVE-2021-0219
Junos OS: Command injection vulnerability in 'request system software' CLI command
Published 2021-01-15 · Modified
7.2EPSS 0.007
CVE-2022-22186
Junos OS: EX4650 Series: Certain traffic received by the Junos OS device on the management interface may be forwarded to egress interfaces instead of discarded
Published 2022-04-14 · Modified
7.2EPSS 0.006
CVE-2018-0053
vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting.
Published 2018-10-10 · Modified
7.2EPSS 0.005
CVE-2018-0008
Junos OS: commit script may allow unauthenticated root login upon reboot
Published 2018-01-10 · Modified
7.2EPSS 0.005
CVE-2019-0035
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
Published 2019-04-10 · Modified
7.2EPSS 0.004
CVE-2014-0615
Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R5, 13.1 before 13.1R3-S1, 13.2 before 13.2R2, and 13.3 before 13.3R1 allows local users to gain privileges via vectors related to "certain combinations of Junos OS CLI commands and arguments."
Published 2014-01-14 · Modified
7.2EPSS 0.004
CVE-2015-3003
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 allows local users to gain privileges via crafted combinations of CLI commands and arguments.
Published 2015-04-10 · Modified
7.2EPSS 0.004
CVE-2015-3007
The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.
Published 2015-07-14 · Modified
7.2EPSS 0.004
CVE-2015-5358
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D16, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (mbuf and connection consumption and restart) via a large number of requests that trigger a TCP connection to move to the LAST_ACK state when there is more data to send.
Published 2015-07-14 · Modified
7.1EPSS 0.026
CVE-2014-2714
The Enhanced Web Filtering (EWF) in Juniper Junos before 10.4R15, 11.4 before 11.4R9, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D10, and 12.1X46 before 12.1X46-D10, as used in the SRX Series services gateways, allows remote attackers to cause a denial of service (flow daemon crash and restart) via a crafted URL.
Published 2014-04-14 · Modified
7.1EPSS 0.024
CVE-2014-0617
Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.
Published 2014-01-14 · Modified
7.1EPSS 0.023
CVE-2013-4686
The kernel in Juniper Junos 10.4 before 10.4R14, 11.4 before 11.4R8, 11.4X27 before 11.4X27.43, 12.1 before 12.1R6, 12.1X44 before 12.1X44-D20, 12.2 before 12.2R4, and 12.3 before 12.3R2, in certain VLAN configurations with unrestricted arp-resp and proxy-arp settings, allows remote attackers to cause a denial of service (device crash) via a crafted ARP request, aka PR 842091.
Published 2013-07-11 · Modified
7.1EPSS 0.023
CVE-2014-0613
The XNM command processor in Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R5, 13.1 before 13.1R3-S1, 13.2 before 13.2R2-S2, and 13.3 before 13.3R1, when xnm-ssl or xnm-clear-text is enabled, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Published 2014-01-14 · Modified
7.1EPSS 0.023
CVE-2016-1276
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause a denial of service (CPU consumption, fab link failure, or flip-flop failovers) via vectors related to in-transit traffic matching ALG rules.
Published 2016-08-05 · Modified
7.1EPSS 0.021
CVE-2014-0616
Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R4-S2, 13.1 before 13.1R3-S1, 13.2 before 13.2R2, and 13.3 before 13.3R1 allows remote attackers to cause a denial of service (rdp crash) via a large BGP UPDATE message which immediately triggers a withdraw message to be sent, as demonstrated by a long AS_PATH and a large number of BGP Communities.
Published 2014-01-14 · Modified
7.1EPSS 0.018
CVE-2015-5359
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R7, 13.3 before 13.3R5, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (NULL pointer dereference and RDP crash) via a large number of BGP-VPLS advertisements with updated BGP local preference values.
Published 2015-07-14 · Modified
7.1EPSS 0.017
← Prev11 / 20Next →