VendorsJuniperjunos12.3x48
Vulnerabilities

Juniper Junos 12.3x48

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

113CVEs
CVE-2018-0024
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Published 2018-07-11 · Modified
7.8EPSS 0.004
CVE-2019-0058
Junos OS: SRX Series: A weakness in the Veriexec subsystem may allow privilege escalation.
Published 2019-10-09 · Modified
7.8EPSS 0.003
CVE-2016-1271
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow local users to gain privileges via crafted combinations of CLI commands and arguments, a different vulnerability than CVE-2015-3003, CVE-2014-3816, and CVE-2014-0615.
Published 2016-04-15 · Modified
7.8EPSS 0.003
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2019-0010
Junos OS: SRX Series: Crafted HTTP traffic may cause UTM to consume all mbufs, leading to Denial of Service
Published 2019-01-15 · Modified
7.5EPSS 0.027
CVE-2018-0062
Junos OS: Denial of Service in J-Web
Published 2018-10-10 · Modified
7.5EPSS 0.023
CVE-2018-15505
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Published 2018-08-18 · Modified
7.5EPSS 0.022
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2017-2347
Junos: Denial of Service vulnerability in rpd daemon
Published 2017-07-14 · Modified
7.5EPSS 0.019
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2017-10614
Junos OS: A remote unauthenticated attacker can consume large amounts of CPU and/or memory through telnetd
Published 2017-10-13 · Modified
7.5EPSS 0.017
CVE-2019-0013
Junos OS: RPD crash upon receipt of malformed PIM packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0012
Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2018-0051
Junos OS: Denial of Service vulnerability in MS-PIC, MS-MIC, MS-MPC, MS-DPC and SRX flow daemon (flowd) related to SIP ALG
Published 2018-10-10 · Modified
7.5EPSS 0.016
CVE-2018-0018
SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.
Published 2018-04-11 · Modified
7.5EPSS 0.016
CVE-2019-0044
Junos OS: SRX5000 series: Kernel crash (vmcore) upon receipt of a specific packet on fxp0 interface
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2017-10619
Junos: SRX cluster denial of service vulnerability in flowd due to multicast packets
Published 2017-10-13 · Modified
7.5EPSS 0.013
CVE-2017-2314
Junos: RPD crash due to malformed BGP OPEN message
Published 2017-07-14 · Modified
7.5EPSS 0.013
CVE-2020-1657
Junos OS: SRX Series: An attacker sending spoofed packets to IPSec peers may cause a Denial of Service.
Published 2020-10-16 · Modified
7.5EPSS 0.013
CVE-2020-1634
Junos OS: High-End SRX Series: Multicast traffic might cause all FPCs to reset.
Published 2020-04-08 · Modified
7.5EPSS 0.013
CVE-2016-1270
The rpd daemon in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R6, 14.1 before 14.1R4, and 14.2 before 14.2R2, when configured with BGP-based L2VPN or VPLS, allows remote attackers to cause a denial of service (daemon restart) via a crafted L2VPN family BGP update.
Published 2016-04-15 · Modified
7.5EPSS 0.013
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
CVE-2020-1639
Junos OS: A crafted Ethernet OAM packet received by Junos may cause the Ethernet OAM connectivity fault management process (CFM) to core.
Published 2020-04-08 · Modified
7.5EPSS 0.011
CVE-2019-0051
SRX5000 Series: Denial of Service vulnerability in SSL-Proxy feature.
Published 2019-10-09 · Modified
7.5EPSS 0.011
CVE-2020-1684
Junos OS: SRX Series: High CPU load due to processing for HTTP traffic when Application Identification is enabled.
Published 2020-10-16 · Modified
7.5EPSS 0.011
CVE-2017-10610
SRX Series: Embedded ICMP may cause the flowd process to crash
Published 2017-10-13 · Modified
7.5EPSS 0.011
CVE-2017-10608
SRX series: Junos OS: SRX series using IPv6 Sun/MS-RPC ALGs may experience flowd crash on processing packets.
Published 2017-10-13 · Modified
7.5EPSS 0.010
CVE-2020-1607
Junos OS: Cross-Site Scripting (XSS) in J-Web
Published 2020-01-15 · Modified
7.5EPSS 0.009
CVE-2017-10620
SRX Series: Antivirus updates are downloaded without verification
Published 2017-10-13 · Modified
7.4EPSS 0.006
CVE-2020-1637
Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
Published 2020-04-08 · Modified
7.2EPSS 0.008
CVE-2018-0008
Junos OS: commit script may allow unauthenticated root login upon reboot
Published 2018-01-10 · Modified
7.2EPSS 0.005
CVE-2015-3003
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 allows local users to gain privileges via crafted combinations of CLI commands and arguments.
Published 2015-04-10 · Modified
7.2EPSS 0.004
CVE-2015-3007
The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.
Published 2015-07-14 · Modified
7.2EPSS 0.004
CVE-2015-5358
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D16, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (mbuf and connection consumption and restart) via a large number of requests that trigger a TCP connection to move to the LAST_ACK state when there is more data to send.
Published 2015-07-14 · Modified
7.1EPSS 0.026
CVE-2016-1276
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause a denial of service (CPU consumption, fab link failure, or flip-flop failovers) via vectors related to in-transit traffic matching ALG rules.
Published 2016-08-05 · Modified
7.1EPSS 0.021
CVE-2015-5359
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R7, 13.3 before 13.3R5, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (NULL pointer dereference and RDP crash) via a large number of BGP-VPLS advertisements with updated BGP local preference values.
Published 2015-07-14 · Modified
7.1EPSS 0.017
← Prev2 / 3Next →