VendorsJuniperjunosany version
Vulnerabilities

Juniper Junos any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

278CVEs
CVE-2019-0057
NFX Series: An attacker may be able to take control of the JDM application and subsequently the entire system.
Published 2019-10-09 · Modified
7.8EPSS 0.004
CVE-2016-1271
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow local users to gain privileges via crafted combinations of CLI commands and arguments, a different vulnerability than CVE-2015-3003, CVE-2014-3816, and CVE-2014-0615.
Published 2016-04-15 · Modified
7.8EPSS 0.003
CVE-2022-22162
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in
Published 2022-01-19 · Modified
7.8EPSS 0.002
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2022-22251
cSRX Series: Storing Passwords in a Recoverable Format and software permissions issues allows a local attacker to elevate privileges
Published 2022-10-18 · Modified
7.8EPSS 0.002
CVE-2025-30644
Junos OS: EX2300, EX3400, EX4000 Series, QFX5k Series: Receipt of a specific DHCP packet causes FPC crash when DHCP Option 82 is enabled
Published 2025-04-09 · Analyzed
7.7EPSS 0.003
CVE-2023-4481
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Published 2023-08-31 · Modified
7.5EPSS 0.182
CVE-2018-0017
SRX Series: Denial of service vulnerability in flowd daemon on devices configured with NAT-PT
Published 2018-04-11 · Modified
7.5EPSS 0.019
CVE-2017-2300
On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets.
Published 2017-05-30 · Modified
7.5EPSS 0.018
CVE-2019-0031
Junos OS: jdhcpd daemon memory consumption Denial of Service when receiving specific IPv6 DHCP packets.
Published 2019-04-10 · Modified
7.5EPSS 0.017
CVE-2019-0033
SRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2016-1270
The rpd daemon in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R6, 14.1 before 14.1R4, and 14.2 before 14.2R2, when configured with BGP-based L2VPN or VPLS, allows remote attackers to cause a denial of service (daemon restart) via a crafted L2VPN family BGP update.
Published 2016-04-15 · Modified
7.5EPSS 0.013
CVE-2022-22197
Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening
Published 2022-04-14 · Modified
7.5EPSS 0.011
CVE-2022-22161
Junos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2022-01-19 · Modified
7.5EPSS 0.010
CVE-2022-22153
SRX Series and MX Series with SPC3: A high percentage of fragments might lead to high latency or packet drops
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2022-22223
Junos OS: QFX10000 Series: In IP/MPLS PHP node scenarios upon receipt of certain crafted packets multiple interfaces in LAG configurations may detach.
Published 2022-10-18 · Modified
7.5EPSS 0.008
CVE-2023-22410
Junos OS: MX Series with MPC10/MPC11: When Suspicious Control Flow Detection (scfd) is enabled and an attacker is sending specific traffic, this causes a memory leak.
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2023-22415
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2022-22201
SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-22416
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is received
Published 2023-01-12 · Modified
7.5EPSS 0.007
CVE-2023-28964
Junos OS and Junos OS Evolved: Malformed BGP flowspec update causes RPD crash
Published 2023-04-17 · Modified
7.5EPSS 0.006
CVE-2023-0026
2023-06: Out-of-Cycle Security Bulletin: Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute
Published 2023-06-21 · Modified
7.5EPSS 0.006
CVE-2023-22403
Junos OS: QFX10K Series: An ICCP flap will be observed due to excessive specific traffic
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-22413
Junos OS: MX Series: The Multiservices PIC Management Daemon (mspmand) will crash when an IPsec6 tunnel processes specific IPv4 packets
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-36832
Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28985
SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28965
Junos OS: QFX10002: Failure of storm control feature may lead to Denial of Service
Published 2023-04-17 · Modified
7.5EPSS 0.006
CVE-2023-28976
Junos OS: MX Series: If a specific traffic rate goes above the DDoS threshold it will lead to an FPC crash
Published 2023-04-17 · Modified
7.5EPSS 0.006
CVE-2023-22391
Junos OS: ACX2K Series: Receipt of a high rate of specific traffic will lead to a Denial of Service (DoS)
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-22394
Junos OS: SRX Series and MX Series: Memory leak due to receipt of specially crafted SIP calls
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2022-22173
Junos OS: CRL failing to download causes a memory leak and ultimately a DoS
Published 2022-01-19 · Modified
7.5EPSS 0.006
CVE-2024-21606
Junos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crash
Published 2024-01-12 · Modified
7.5EPSS 0.006
CVE-2023-36843
Junos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabled
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-44199
Junos OS: MX Series: In a PTP scenario a prolonged routing protocol churn can trigger an FPC reboot
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-44186
Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor
Published 2023-10-11 · Modified
7.5EPSS 0.005
CVE-2023-44181
Junos OS: QFX5k: l2 loop in the overlay impacts the stability in a EVPN/VXLAN environment
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-44185
Junos OS and Junos OS Evolved: In an BGP scenario RPD crashes upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-36841
Junos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of Service
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-44197
Junos OS and Junos OS Evolved: An rpd crash may occur when BGP is processing newly learned routes
Published 2023-10-12 · Modified
7.5EPSS 0.005
← Prev3 / 7Next →