VendorsJuniperjunos17.3
Vulnerabilities

Juniper Junos 17.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

171CVEs
CVE-2021-31374
Junos OS and Junos OS Evolved: RPD crash while processing a specially crafted BGP UPDATE or KEEPALIVE message.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31351
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2020-1646
Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.
Published 2020-07-17 · Modified
7.5EPSS 0.010
CVE-2021-31378
Junos OS: An attacker sending spoofed RADIUS messages to a Junos OS device configured for broadband services may cause broadband subscribers to remain stuck in a "Terminating" state.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-0285
Junos OS: QFX5000 Series and EX4600 Series: Continuous traffic destined to a device configured with MC-LAG leading to nodes losing their control connection which can impact traffic
Published 2021-07-15 · Modified
7.5EPSS 0.010
CVE-2021-0230
Junos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statistics
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2021-0282
Junos OS: RPD crash while processing a specific BGP UPDATE when Multipath or add-path features are enabled
Published 2021-07-15 · Modified
7.5EPSS 0.010
CVE-2021-0260
Junos OS: SNMP fails to properly perform authorization checks on incoming received SNMP requests.
Published 2021-04-22 · Modified
7.5EPSS 0.009
CVE-2020-1607
Junos OS: Cross-Site Scripting (XSS) in J-Web
Published 2020-01-15 · Modified
7.5EPSS 0.009
CVE-2021-0281
Junos OS and Junos OS Evolved: Specific packets can trigger rpd crash when BGP Origin Validation is configured with RPKI
Published 2021-07-15 · Modified
7.5EPSS 0.008
CVE-2023-22396
Junos OS: Receipt of crafted TCP packets destined to the device results in MBUF leak leading to a Denial of Service (DoS)
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2021-0222
Junos OS: Upon receipt of certain protocol packets with invalid payloads a self-propagating Denial of Service may occur.
Published 2021-01-15 · Modified
7.4EPSS 0.006
CVE-2021-0244
Junos OS: A race condition in the storm control profile may allow an attacker to cause a Denial of Service condition
Published 2021-04-22 · Modified
7.4EPSS 0.006
CVE-2021-0241
Junos OS: Receipt of specific DHCPv6 packet may cause jdhcpd to crash and restart
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2021-0240
Junos OS: Receipt of malformed DHCPv6 packets causes jdhcpd to crash and restart.
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2021-0259
Junos OS and Junos OS Evolved: QFX5K Series: Underlay network traffic might not be processed upon receipt of high rate of specific genuine overlay packets in VXLAN scenario
Published 2021-04-22 · Modified
7.4EPSS 0.004
CVE-2020-1637
Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
Published 2020-04-08 · Modified
7.2EPSS 0.008
CVE-2021-31375
Junos OS: Receipt of a specific BGP update may cause RPKI policy-checks to be bypassed
Published 2021-10-19 · Modified
7.2EPSS 0.008
CVE-2021-0219
Junos OS: Command injection vulnerability in 'request system software' CLI command
Published 2021-01-15 · Modified
7.2EPSS 0.007
CVE-2019-0035
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
Published 2019-04-10 · Modified
7.2EPSS 0.004
CVE-2021-0258
Junos OS: Kernel panic upon receipt of specific TCPv6 packet on management interface
Published 2021-04-22 · Modified
7.1EPSS 0.006
CVE-2019-0073
Junos OS: PKI key pairs are exported with insecure file permissions
Published 2019-10-09 · Modified
7.1EPSS 0.003
CVE-2020-1618
Junos OS: EX and QFX Series: Console port authentication bypass vulnerability
Published 2020-04-08 · Modified
6.9EPSS 0.004
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2020-1600
Junos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.
Published 2020-01-15 · Modified
6.8EPSS 0.012
CVE-2021-0210
Junos OS: Privilege escalation in J-Web due to arbitrary command and code execution via information disclosure from another users active session
Published 2021-01-15 · Modified
6.8EPSS 0.011
CVE-2021-0247
Junos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration.
Published 2021-04-22 · Modified
6.8EPSS 0.006
CVE-2022-22154
Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
Published 2022-01-19 · Modified
6.8EPSS 0.002
CVE-2020-1619
Junos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulnerability in NG-RE.
Published 2020-04-08 · Modified
6.7EPSS 0.003
CVE-2021-0291
Junos OS and Junos OS Evolved: A vulnerability allows a network based unauthenticated attacker which sends a high rate of specific traffic to cause a partial Denial of Service
Published 2021-07-15 · Modified
6.5EPSS 0.010
CVE-2017-10611
Junos: EX Series PFE and MX MPC7E/8E/9E PFE crash when fetching interface stats with 'extended-statistics' enabled
Published 2017-10-13 · Modified
6.5EPSS 0.009
CVE-2020-1604
Junos OS: EX4300/EX4600/QFX3500/QFX5100 Series: Stateless IP firewall filter may fail to evaluate certain packets
Published 2020-01-15 · Modified
6.5EPSS 0.008
CVE-2020-1625
Junos OS: Kernel memory leak in virtual-memory due to interface flaps
Published 2020-04-08 · Modified
6.5EPSS 0.008
CVE-2021-0215
Junos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flaps
Published 2021-01-15 · Modified
6.5EPSS 0.008
CVE-2019-0038
SRX Series: Crafted packets destined to fxp0 management interface on SRX340/SRX345 devices can lead to DoS
Published 2019-04-10 · Modified
6.5EPSS 0.007
CVE-2019-0046
Junos OS: EX4300 Series: Denial of Service upon receipt of large number of specific valid packets on management interface.
Published 2019-07-11 · Modified
6.5EPSS 0.007
CVE-2018-0054
QFX5000/EX4600 Series: Routing protocol flap upon receipt of high rate of Ethernet frames
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2018-0063
Junos OS: Nexthop index allocation failed: private index space exhausted after incoming ARP requests to management interface
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2019-0011
Junos OS: Kernel crash after processing specific incoming packet to the out of band management interface (CVE-2019-0011)
Published 2019-01-15 · Modified
6.5EPSS 0.006
CVE-2018-0056
MX Series: L2ALD daemon may crash if a duplicate MAC is learned by two different interfaces
Published 2018-10-10 · Modified
6.5EPSS 0.006
← Prev3 / 5Next →