VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2025-21595
Junos OS and Junos OS Evolved: In an EVPN-VXLAN scenario specific ARP or NDP packets cause FPC to crash
Published 2025-04-09 · Analyzed
7.1EPSS 0.003
CVE-2026-21909
Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash
Published 2026-01-15 · Analyzed
7.1EPSS 0.003
CVE-2024-39560
Junos OS and Junos OS Evolved: Memory leak due to RSVP neighbor persistent error leading to kernel crash
Published 2024-07-10 · Analyzed
7.1EPSS 0.002
CVE-2024-39514
Junos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crash
Published 2024-07-10 · Analyzed
7.1EPSS 0.002
CVE-2024-39517
Junos OS and Junos OS Evolved: Upon processing specific L2 traffic, rpd can hang in devices with EVPN/VXLAN configured
Published 2024-07-10 · Analyzed
7.1EPSS 0.002
CVE-2025-30646
Junos OS and Junos OS Evolved: Receipt of a malformed LLDP TLV results in l2cpd crash
Published 2025-04-09 · Analyzed
7.1EPSS 0.002
CVE-2025-30647
Junos OS: MX Series: Subscriber login/logout activity will lead to a memory leak
Published 2025-04-09 · Analyzed
7.1EPSS 0.002
CVE-2025-21600
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash
Published 2025-01-09 · Analyzed
7.1EPSS 0.002
CVE-2025-21602
Junos OS and Junos OS Evolved: Receipt of specially crafted BGP update packet causes RPD crash
Published 2025-01-09 · Analyzed
7.1EPSS 0.002
CVE-2025-21593
Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash
Published 2025-01-09 · Analyzed
7.1EPSS 0.002
CVE-2026-21919
Junos OS and Junos OS Evolved: A high frequency of connecting and disconnecting NETCONF sessions causes management unavailability
Published 2026-04-09 · Analyzed
7.1EPSS 0.002
CVE-2024-30387
Junos OS: ACX5448 & ACX710: Due to interface flaps the PFE process can crash
Published 2024-04-12 · Analyzed
7.1EPSS 0.002
CVE-2021-31360
Junos OS and Junos OS Evolved: Denial of Service vulnerability in local file processing
Published 2021-10-19 · Modified
7.1EPSS 0.002
CVE-2024-39556
Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow
Published 2024-07-10 · Analyzed
7.1EPSS 0.001
CVE-2025-59957
Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor
Published 2025-10-09 · Analyzed
7.0EPSS 0.002
CVE-2024-30409
Junos OS and Junos OS Evolved: Higher CPU consumption on routing engine leads to Denial of Service (DoS).
Published 2024-04-12 · Analyzed
6.9EPSS 0.005
CVE-2026-57021
Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash
Published 2026-07-09 · Analyzed
6.9EPSS 0.005
CVE-2025-60011
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap
Published 2026-01-15 · Analyzed
6.9EPSS 0.005
CVE-2026-57024
Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2025-30657
Junos OS: Processing of a specific BGP update causes the SRRD process to crash
Published 2025-04-09 · Analyzed
6.9EPSS 0.004
CVE-2015-3002
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stanza, which allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.
Published 2015-04-10 · Modified
6.9EPSS 0.004
CVE-2026-57054
Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2024-30389
Junos OS: EX4300 Series: Firewall filter not blocking egress traffic
Published 2024-04-12 · Analyzed
6.9EPSS 0.004
CVE-2024-30410
Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.
Published 2024-04-12 · Analyzed
6.9EPSS 0.004
CVE-2020-1618
Junos OS: EX and QFX Series: Console port authentication bypass vulnerability
Published 2020-04-08 · Modified
6.9EPSS 0.004
CVE-2015-7751
Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D105, 14.1X51 before 14.1X51-D70, 14.1X53 before 14.1X53-D25, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R1, 15.1 before 15.1F2 or 15.1R1, and 15.1X49 before 15.1X49-D10 does not require a password for the root user when pam.conf is "corrupted," which allows local users to gain root privileges by modifying the file.
Published 2015-10-19 · Modified
6.9EPSS 0.004
CVE-2014-6384
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quotes in authorization attributes in the TACACS+ configuration, which allows local users to bypass the security policy and execute commands via unspecified vectors.
Published 2015-01-16 · Modified
6.9EPSS 0.003
CVE-2025-52951
Junos OS: IPv6 firewall filter fails to match payload-protocol
Published 2025-07-11 · Analyzed
6.9EPSS 0.003
CVE-2024-39561
Junos OS: SRX4600, SRX5000 Series: TCP packets with SYN/FIN or SYN/RST are transferred after enabling no-syn-check with Express Path
Published 2024-07-10 · Analyzed
6.9EPSS 0.003
CVE-2026-33773
Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physical interface one of those is not applied
Published 2026-04-09 · Analyzed
6.9EPSS 0.003
CVE-2024-39533
Junos OS: QFX5000 Series and EX4600 Series: Output firewall filter is not applied if certain match criteria are used
Published 2024-07-11 · Analyzed
6.9EPSS 0.003
CVE-2025-59980
Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed
Published 2025-10-09 · Analyzed
6.9EPSS 0.003
CVE-2024-47507
Junos OS and Junos OS Evolved: BGP update message containing aggregator attribute with an ASN value of zero (0) is accepted
Published 2024-10-11 · Analyzed
6.9EPSS 0.003
CVE-2026-33774
Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
Published 2026-04-09 · Analyzed
6.9EPSS 0.003
CVE-2025-6549
Junos OS: SRX Series: J-Web can be exposed on additional interfaces
Published 2025-07-11 · Analyzed
6.9EPSS 0.002
CVE-2024-30378
Junos OS: MX Series: bbe-smgd process crash upon execution of specific CLI commands
Published 2024-04-16 · Analyzed
6.9EPSS 0.002
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2013-6013
Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 12.1X45-D10 on SRX devices, when using telnet pass-through authentication on the firewall, might allow remote attackers to execute arbitrary code via a crafted telnet message.
Published 2013-10-17 · Modified
6.8EPSS 0.040
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2014-3825
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted packet.
Published 2014-10-14 · Modified
6.8EPSS 0.020
← Prev13 / 20Next →