VendorsJuniperjunos15.1x53
Vulnerabilities

Juniper Junos 15.1x53

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

83CVEs
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2017-2304
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'
Published 2017-05-30 · Modified
7.5EPSS 0.018
CVE-2017-10614
Junos OS: A remote unauthenticated attacker can consume large amounts of CPU and/or memory through telnetd
Published 2017-10-13 · Modified
7.5EPSS 0.017
CVE-2019-0013
Junos OS: RPD crash upon receipt of malformed PIM packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0012
Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2017-2314
Junos: RPD crash due to malformed BGP OPEN message
Published 2017-07-14 · Modified
7.5EPSS 0.013
CVE-2017-2348
Junos OS: jdhcpd daemon crash due to invalid IPv6 UDP packets
Published 2017-07-14 · Modified
7.5EPSS 0.013
CVE-2020-1639
Junos OS: A crafted Ethernet OAM packet received by Junos may cause the Ethernet OAM connectivity fault management process (CFM) to core.
Published 2020-04-08 · Modified
7.5EPSS 0.011
CVE-2020-1601
Junos OS: Upon receipt of certain types of malformed PCEP packets the pccd process may crash.
Published 2020-01-15 · Modified
7.5EPSS 0.011
CVE-2020-1607
Junos OS: Cross-Site Scripting (XSS) in J-Web
Published 2020-01-15 · Modified
7.5EPSS 0.009
CVE-2018-0008
Junos OS: commit script may allow unauthenticated root login upon reboot
Published 2018-01-10 · Modified
7.2EPSS 0.005
CVE-2019-0035
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
Published 2019-04-10 · Modified
7.2EPSS 0.004
CVE-2018-0004
Junos OS: Kernel Denial of Service Vulnerability
Published 2018-01-10 · Modified
7.1EPSS 0.012
CVE-2020-1618
Junos OS: EX and QFX Series: Console port authentication bypass vulnerability
Published 2020-04-08 · Modified
6.9EPSS 0.004
CVE-2017-2312
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process. Over time, repeatedly receiving this type of LDP packet(s) will cause the memory to exhaust and the rpd process to crash and restart. It is not possible to free up the memory that has been consumed without restarting the rpd process. This issue affects Junos OS based devices with either IPv4 or IPv6 LDP enabled via the [protocols ldp] configuration (the native IPv6 support for LDP is available in Junos OS 16.1 and higher). The interface on which the packet arrives needs to have LDP enabled. The affected Junos versions are: 13.3 prior to 13.3R10; 14.1 prior to 14.1R8; 14.2 prior to 14.2R7-S6 or 14.2R8; 15.1 prior to 15.1F2-S14, 15.1F6-S4, 15.1F7, 15.1R4-S7, 15.1R5; 15.1X49 before 15.1X49-D70; 15.1X53 before 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 before 16.1R2. 16.2R1 and all subsequent releases have a resolution for this vulnerability.
Published 2017-04-24 · Modified
6.8EPSS 0.016
CVE-2020-1600
Junos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.
Published 2020-01-15 · Modified
6.8EPSS 0.012
CVE-2021-0247
Junos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration.
Published 2021-04-22 · Modified
6.8EPSS 0.006
CVE-2018-0003
Junos OS: A crafted MPLS packet may lead to a kernel crash
Published 2018-01-10 · Modified
6.5EPSS 0.009
CVE-2021-0215
Junos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flaps
Published 2021-01-15 · Modified
6.5EPSS 0.008
CVE-2016-1280
PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1R4, 15.1X49 before 15.1X49-D20, 15.1X53 before 15.1X53-D60, and 16.1 before 16.1R1 allow remote attackers to bypass an intended certificate validation mechanism via a self-signed certificate with an Issuer name that matches a valid CA certificate enrolled in Junos.
Published 2016-09-09 · Modified
6.5EPSS 0.007
CVE-2018-0054
QFX5000/EX4600 Series: Routing protocol flap upon receipt of high rate of Ethernet frames
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2018-0055
Junos OS: jdhcpd process crash during processing of specially crafted DHCPv6 message
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2018-0029
Junos OS: Kernel crash (vmcore) during broadcast storm after enabling 'monitor traffic interface fxp0'
Published 2018-07-11 · Modified
6.5EPSS 0.006
CVE-2020-1641
Junos OS: A race condition on receipt of crafted LLDP packets leads to a memory leak and an LLDP crash.
Published 2020-07-17 · Modified
6.5EPSS 0.004
CVE-2018-0034
Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
Published 2018-07-11 · Modified
5.9EPSS 0.021
CVE-2017-10618
Junos: RPD core due to BGP UPDATE with malformed optional transitive attributes
Published 2017-10-13 · Modified
5.9EPSS 0.015
CVE-2018-0019
Junos: Denial of service vulnerability in SNMP MIB-II subagent daemon (mib2d).
Published 2018-04-11 · Modified
5.9EPSS 0.015
CVE-2018-0031
Junos OS: Receipt of specially crafted UDP packets over MPLS may bypass stateless IP firewall rules
Published 2018-07-11 · Modified
5.9EPSS 0.012
CVE-2018-0060
Junos OS: Invalid IP/mask learned from DHCP server might cause device control daemon (dcd) process crash
Published 2018-10-10 · Modified
5.9EPSS 0.011
CVE-2016-1273
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
Published 2016-04-15 · Modified
5.9EPSS 0.007
CVE-2019-0069
Junos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear text
Published 2019-10-09 · Modified
5.9EPSS 0.002
CVE-2019-0009
Junos OS: EX2300 and EX3400: High disk I/O operations may disrupt the communication between RE and PFE
Published 2019-01-15 · Modified
5.5EPSS 0.004
CVE-2020-1643
Junos OS: EX Series: RPD crash when executing specific "show ospf interface" commands from the CLI with OSPF authentication configured
Published 2020-07-17 · Modified
5.5EPSS 0.003
CVE-2017-10613
Junos OS: A kernel hang may occur due to a specific loopback filter action command
Published 2017-10-13 · Modified
5.5EPSS 0.003
CVE-2020-1630
Junos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.
Published 2020-04-08 · Modified
5.5EPSS 0.002
CVE-2018-0061
Junos OS: Denial of service in telnetd
Published 2018-10-10 · Modified
5.3EPSS 0.023
CVE-2017-10621
Junos OS: Denial of service vulnerability in telnetd
Published 2017-10-13 · Modified
5.3EPSS 0.018
CVE-2020-1680
Junos OS: MX Series: MS-MPC/MIC might crash when processing malformed IPv6 packet in NAT64 configuration.
Published 2020-10-16 · Modified
5.3EPSS 0.013
← Prev2 / 3Next →