VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2017-2312
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process. Over time, repeatedly receiving this type of LDP packet(s) will cause the memory to exhaust and the rpd process to crash and restart. It is not possible to free up the memory that has been consumed without restarting the rpd process. This issue affects Junos OS based devices with either IPv4 or IPv6 LDP enabled via the [protocols ldp] configuration (the native IPv6 support for LDP is available in Junos OS 16.1 and higher). The interface on which the packet arrives needs to have LDP enabled. The affected Junos versions are: 13.3 prior to 13.3R10; 14.1 prior to 14.1R8; 14.2 prior to 14.2R7-S6 or 14.2R8; 15.1 prior to 15.1F2-S14, 15.1F6-S4, 15.1F7, 15.1R4-S7, 15.1R5; 15.1X49 before 15.1X49-D70; 15.1X53 before 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 before 16.1R2. 16.2R1 and all subsequent releases have a resolution for this vulnerability.
Published 2017-04-24 · Modified
6.8EPSS 0.016
CVE-2021-0231
Junos OS: SRX, vSRX Series: J-Web Path traversal vulnerability in SRX and vSRX Series leads to information disclosure.
Published 2021-04-22 · Modified
6.8EPSS 0.012
CVE-2020-1600
Junos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.
Published 2020-01-15 · Modified
6.8EPSS 0.012
CVE-2021-0210
Junos OS: Privilege escalation in J-Web due to arbitrary command and code execution via information disclosure from another users active session
Published 2021-01-15 · Modified
6.8EPSS 0.011
CVE-2021-0236
Junos OS: A specific BGP VPNv6 flowspec message causes routing protocol daemon (rpd) process to crash with a core.
Published 2021-04-22 · Modified
6.8EPSS 0.008
CVE-2015-3006
Junos: QFX Series: Insufficient entropy on QFX3500 and QFX3600 platforms when the system boots up
Published 2020-02-28 · Modified
6.8EPSS 0.008
CVE-2021-0247
Junos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration.
Published 2021-04-22 · Modified
6.8EPSS 0.006
CVE-2023-28972
Junos OS: NFX Series: 'set system ports console insecure' allows root password recovery
Published 2023-04-17 · Modified
6.8EPSS 0.004
CVE-2022-22154
Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
Published 2022-01-19 · Modified
6.8EPSS 0.002
CVE-2024-39527
Junos OS: SRX Series: Low privileged user able to access sensitive information on file system
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2024-47501
Junos OS: MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C: In a VPLS or Junos Fusion scenario specific show commands cause FPCs to crash
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2024-47496
Junos OS: MX Series: The PFE will crash on running specific command
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2025-30654
Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information
Published 2025-04-09 · Analyzed
6.8EPSS 0.002
CVE-2024-30384
Junos OS: EX4300 Series: If a specific CLI command is issued PFE crashes will occur
Published 2024-04-12 · Analyzed
6.8EPSS 0.002
CVE-2025-21592
Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system
Published 2025-01-09 · Analyzed
6.8EPSS 0.002
CVE-2025-30652
Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configured causes an rpd crash
Published 2025-04-09 · Analyzed
6.8EPSS 0.002
CVE-2025-21596
Junos OS: SRX1500,SRX4100,SRX4200: Execution of low-privileged CLI command results in chassisd crash
Published 2025-01-09 · Analyzed
6.8EPSS 0.002
CVE-2024-39511
Junos OS: The 802.1X Authentication Daemon crashes on running a specific command
Published 2024-07-10 · Analyzed
6.8EPSS 0.001
CVE-2025-30655
Junos OS and Junos OS Evolved: A specific CLI command will cause an RPD crash when rib-sharding and update-threading is enabled
Published 2025-04-09 · Analyzed
6.8EPSS 0.001
CVE-2025-59959
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
Published 2026-01-15 · Modified
6.8EPSS 0.001
CVE-2026-57025
Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
Published 2026-07-09 · Modified
6.8EPSS 0.001
CVE-2025-52963
Junos OS: A low-privileged user can disable an interface
Published 2025-07-11 · Analyzed
6.8EPSS 0.001
CVE-2026-33786
Junos OS: SRX1600, SRX2300, SRX4300: When a specific show command is executed chassisd crashes
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2026-33787
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600: When a specific show command is executed chassisd crashes
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2025-59961
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2026-33776
Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2026-33802
Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
Published 2026-07-09 · Analyzed
6.8EPSS 0.001
CVE-2025-52989
Junos OS and Junos OS Evolved: Annotate configuration command can be used to change the configuration
Published 2025-07-11 · Analyzed
6.8EPSS 0.001
CVE-2025-52986
Junos OS and Junos OS Evolved: When RIB sharding is configured each time a show command is executed RPD memory leaks
Published 2025-07-11 · Analyzed
6.8EPSS 0.001
CVE-2026-21912
Junos OS: MX10k Series: 'show system firmware' CLI command may lead to LC480 or LC2101 line card reset
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2025-21590
Junos OS: An local attacker with shell access can execute arbitrary code
Published 2025-03-12 · Analyzed
6.7KEVEPSS 0.017
CVE-2020-1619
Junos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulnerability in NG-RE.
Published 2020-04-08 · Modified
6.7EPSS 0.003
CVE-2016-1267
Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R3-S4, 15.1 before 15.1F2, or 15.1R2, 15.1X49 before 15.1X49-D20, and 16.1 before 16.1R1 allows local users to read, delete, or modify arbitrary files via unspecified vectors.
Published 2016-04-15 · Modified
6.7EPSS 0.002
CVE-2026-21901
Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash
Published 2026-07-09 · Analyzed
6.7EPSS 0.002
CVE-2022-22203
Junos OS: EX4600 Series and QFX5000 Series: Receipt of specific traffic will lead to an fxpc process crash followed by an FPC reboot
Published 2022-07-20 · Modified
6.5EPSS 0.011
CVE-2021-0291
Junos OS and Junos OS Evolved: A vulnerability allows a network based unauthenticated attacker which sends a high rate of specific traffic to cause a partial Denial of Service
Published 2021-07-15 · Modified
6.5EPSS 0.010
CVE-2016-1275
Juniper Junos OS before 13.3R9, 14.1R6 before 14.1R6-S1, and 14.1 before 14.1R7, when configured with VPLS routing-instances, allows remote attackers to obtain sensitive mbuf information by injecting a flood of Ethernet frames with IPv6 MAC addresses directly into a connected interface.
Published 2016-09-09 · Modified
6.5EPSS 0.009
CVE-2018-0003
Junos OS: A crafted MPLS packet may lead to a kernel crash
Published 2018-01-10 · Modified
6.5EPSS 0.009
CVE-2017-10611
Junos: EX Series PFE and MX MPC7E/8E/9E PFE crash when fetching interface stats with 'extended-statistics' enabled
Published 2017-10-13 · Modified
6.5EPSS 0.009
← Prev14 / 20Next →