VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2021-0268
Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
Published 2021-04-22 · Modified
9.3EPSS 0.009
CVE-2013-6014
Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an unnumbered interface, allows remote attackers to perform ARP poisoning attacks and possibly obtain sensitive information via a crafted ARP message.
Published 2013-10-28 · Modified
9.3EPSS 0.008
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2019-0040
Junos OS: Specially crafted packets sent to port 111 on any interface triggers responses from the management interface
Published 2019-04-10 · Modified
9.1EPSS 0.019
CVE-2013-6618
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.
Published 2013-11-05 · Modified
9.01 PoCEPSS 0.106
CVE-2014-3816
Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8-S2, 12.3 before 12.3R7, 13.1 before 13.1R4-S2, 13.2 before 13.2R5, 13.3 before 13.3R2-S2, and 14.1 before 14.1R1 allows remote authenticated users to gain privileges via unspecified combinations of CLI commands and arguments.
Published 2014-07-11 · Modified
9.0EPSS 0.022
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2016-1264
Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before 13.2X52-D30, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4, 15.1 before 15.1F2 or 15.1R2, 15.1X49 before 15.1X49-D10 or 15.1X49-D20, and 16.1 before 16.1R1 allows remote authenticated users to gain privileges via the URL option.
Published 2016-04-15 · Modified
8.8EPSS 0.017
CVE-2019-0047
Junos OS: Persistent XSS vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.016
CVE-2020-1673
Junos OS: Reflected Cross-site Scripting vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-10-16 · Modified
8.8EPSS 0.016
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2018-0043
Junos OS: RPD daemon crashes upon receipt of specific MPLS packet
Published 2018-10-10 · Modified
8.8EPSS 0.012
CVE-2018-0045
Junos OS: RPD daemon crashes due to receipt of specific Draft-Rosen MVPN control packet in Draft-Rosen MVPN configuration
Published 2018-10-10 · Modified
8.8EPSS 0.011
CVE-2020-1656
Junos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.
Published 2020-10-16 · Modified
8.8EPSS 0.011
CVE-2019-0062
Junos OS: Session fixation vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.011
CVE-2020-1609
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.009
CVE-2021-0278
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-07-15 · Modified
8.8EPSS 0.009
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2021-0269
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
Published 2021-04-22 · Modified
8.8EPSS 0.009
CVE-2020-1605
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2020-1602
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets may take over the code execution of the JDHCPD process.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2018-0005
Security Bulletin: Junos OS: MAC move limit configured to drop traffic may forward traffic.
Published 2018-01-10 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-0277
Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
Published 2021-07-15 · Modified
8.8EPSS 0.007
CVE-2021-0208
Junos OS and Junos OS Evolved: In bidirectional LSP configurations, on MPLS egress router RPD may core upon receipt of specific malformed RSVP packet.
Published 2021-01-15 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2018-0021
Junos OS: Short MacSec keys may allow man-in-the-middle attacks.
Published 2018-04-11 · Modified
8.8EPSS 0.006
CVE-2023-44182
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
Published 2023-10-12 · Modified
8.8EPSS 0.006
CVE-2024-39565
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
Published 2024-07-10 · Analyzed
8.8EPSS 0.005
CVE-2019-0070
Junos OS: NFX Series: An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions.
Published 2019-10-09 · Modified
8.8EPSS 0.004
CVE-2016-1261
Junos: vulnerabilities in J-Web (CVE-2016-1261)
Published 2017-10-13 · Modified
8.8EPSS 0.004
CVE-2017-2341
Junos OS: VM to host privilege escalation in platforms with Junos OS running in a virtualized environment.
Published 2017-07-14 · Modified
8.8EPSS 0.004
CVE-2026-33785
Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario
Published 2026-04-09 · Analyzed
8.8EPSS 0.001
CVE-2024-39547
Junos OS and Junos OS Evolved: cRPD: Receipt of crafted TCP traffic can trigger high CPU utilization
Published 2024-10-11 · Analyzed
8.7EPSS 0.010
CVE-2024-30382
Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-30392
Junos OS: MX Series with SPC3 and MS-MPC/-MIC: When URL filtering is enabled and a specific URL request is received a flowd crash occurs
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-30394
Junos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crash
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
← Prev2 / 20Next →