VendorsJuniperjunos12.3x48
Vulnerabilities

Juniper Junos 12.3x48

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

113CVEs
CVE-2016-1277
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D40, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R6, 15.1 before 15.1F6 or 15.1R3, and 15.1X49 before 15.1X49-D40, when configured with a GRE or IPIP tunnel, allow remote attackers to cause a denial of service (kernel panic) via a crafted ICMP packet.
Published 2016-09-09 · Modified
7.1EPSS 0.017
CVE-2018-0004
Junos OS: Kernel Denial of Service Vulnerability
Published 2018-01-10 · Modified
7.1EPSS 0.012
CVE-2014-6447
Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, 14.2 before 14.2R1, and 15.1 before 15.1R1.
Published 2020-02-11 · Modified
7.1EPSS 0.009
CVE-2015-7751
Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D105, 14.1X51 before 14.1X51-D70, 14.1X53 before 14.1X53-D25, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R1, 15.1 before 15.1F2 or 15.1R1, and 15.1X49 before 15.1X49-D10 does not require a password for the root user when pam.conf is "corrupted," which allows local users to gain root privileges by modifying the file.
Published 2015-10-19 · Modified
6.9EPSS 0.004
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2020-1600
Junos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.
Published 2020-01-15 · Modified
6.8EPSS 0.012
CVE-2016-1267
Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R3-S4, 15.1 before 15.1F2, or 15.1R2, 15.1X49 before 15.1X49-D20, and 16.1 before 16.1R1 allows local users to read, delete, or modify arbitrary files via unspecified vectors.
Published 2016-04-15 · Modified
6.7EPSS 0.002
CVE-2018-0003
Junos OS: A crafted MPLS packet may lead to a kernel crash
Published 2018-01-10 · Modified
6.5EPSS 0.009
CVE-2016-1280
PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1R4, 15.1X49 before 15.1X49-D20, 15.1X53 before 15.1X53-D60, and 16.1 before 16.1R1 allow remote attackers to bypass an intended certificate validation mechanism via a self-signed certificate with an Issuer name that matches a valid CA certificate enrolled in Junos.
Published 2016-09-09 · Modified
6.5EPSS 0.007
CVE-2015-5361
Junos: FTPS through SRX opens up wide range of data channel TCP ports
Published 2020-02-28 · Modified
6.5EPSS 0.005
CVE-2020-1641
Junos OS: A race condition on receipt of crafted LLDP packets leads to a memory leak and an LLDP crash.
Published 2020-07-17 · Modified
6.5EPSS 0.004
CVE-2020-1688
Junos OS: SRX and NFX Series: Insufficient Web API private key protection
Published 2020-10-16 · Modified
6.5EPSS 0.003
CVE-2018-0034
Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
Published 2018-07-11 · Modified
5.9EPSS 0.021
CVE-2016-1262
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet.
Published 2016-01-15 · Modified
5.9EPSS 0.015
CVE-2018-0019
Junos: Denial of service vulnerability in SNMP MIB-II subagent daemon (mib2d).
Published 2018-04-11 · Modified
5.9EPSS 0.015
CVE-2018-0009
SRX Series: Firewall bypass vulnerability when UUID with leading zeros is configured.
Published 2018-01-10 · Modified
5.9EPSS 0.013
CVE-2018-0031
Junos OS: Receipt of specially crafted UDP packets over MPLS may bypass stateless IP firewall rules
Published 2018-07-11 · Modified
5.9EPSS 0.012
CVE-2018-0060
Junos OS: Invalid IP/mask learned from DHCP server might cause device control daemon (dcd) process crash
Published 2018-10-10 · Modified
5.9EPSS 0.011
CVE-2019-0015
Junos OS: SRX Series: Deleted dynamic VPN users are allowed to establish VPN connections until reboot
Published 2019-01-15 · Modified
5.5EPSS 0.008
CVE-2020-1643
Junos OS: EX Series: RPD crash when executing specific "show ospf interface" commands from the CLI with OSPF authentication configured
Published 2020-07-17 · Modified
5.5EPSS 0.003
CVE-2017-10613
Junos OS: A kernel hang may occur due to a specific loopback filter action command
Published 2017-10-13 · Modified
5.5EPSS 0.003
CVE-2020-1630
Junos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.
Published 2020-04-08 · Modified
5.5EPSS 0.002
CVE-2018-0061
Junos OS: Denial of service in telnetd
Published 2018-10-10 · Modified
5.3EPSS 0.023
CVE-2017-10621
Junos OS: Denial of service vulnerability in telnetd
Published 2017-10-13 · Modified
5.3EPSS 0.018
CVE-2016-1256
Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R7, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D18 or 14.1X53-D30, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R4, 15.1 before 15.1R2, and 15.1X49 before 15.1X49-D10 allow remote attackers to cause a denial of service via a malformed IGMPv3 packet, aka a "multicast denial of service."
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2016-1258
Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R8, 14.1 before 14.1R6, and 14.2 before 14.2R5, allows remote attackers to cause a denial of service (J-Web crash) via unspecified vectors.
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2020-1661
Junos OS: jdhcpd process crash when forwarding a malformed DHCP packet.
Published 2020-10-16 · Modified
5.3EPSS 0.010
CVE-2017-10604
Junos OS: SRX Series: Cluster configuration sync failures occur if the root user account is locked out
Published 2017-07-14 · Modified
5.3EPSS 0.009
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562
CVE-2015-5360
IPv6 sendd in Juniper Junos 12.1X44 before 12.1X44-D51, 12.1X46 before 12.1X46-D36, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D20, when the "set protocols neighbor-discovery secure security-level default" option is configured, allows remote attackers to cause a denial of service (CPU consumption) via a crafted Secure Neighbor Discovery (SEND) Protocol packet.
Published 2015-07-16 · Modified
5.0EPSS 0.018
CVE-2014-6449
Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R5, and 14.2 before 14.2R1 do not properly handle TCP packet reassembly, which allows remote attackers to cause a denial of service (buffer consumption) via a crafted sequence of packets "destined to the device."
Published 2015-10-16 · Modified
5.0EPSS 0.017
CVE-2015-5363
The SRX Network Security Daemon (nsd) in Juniper SRX Series services gateways with Junos 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 allows remote DNS servers to cause a denial of service (crash) via a crafted DNS response.
Published 2015-07-16 · Modified
5.0EPSS 0.013
CVE-2015-3004
J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D10, 12.3X48 before 12.3X48-D10, 12.2 before 12.2R9, 12.3 before 12.3R7, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R5, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, and 14.2 before 14.2R1 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
Published 2015-04-10 · Modified
4.3EPSS 0.018
← Prev3 / 3