VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2026-21917
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2025-30659
Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-21594
Junos OS: MX Series: In DS-lite and NAT scenario receipt of crafted IPv6 traffic causes port block
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30658
Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21918
Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-21913
Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2025-59964
Junos OS: SRX4700: When forwarding-options sampling is enabled any traffic destined to the RE will cause the forwarding line card to crash and restart
Published 2025-10-09 · Analyzed
8.7EPSS 0.004
CVE-2024-30397
Junos OS: An invalid certificate causes a Denial of Service in the Internet Key Exchange (IKE) process
Published 2024-04-12 · Modified
8.7EPSS 0.003
CVE-2026-21914
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.003
CVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Published 2016-03-09 · Modified
8.6EPSS 0.621
CVE-2017-10605
Junos: SRX Series denial of service vulnerability in flowd due to crafted DHCP packet
Published 2017-07-14 · Modified
8.6EPSS 0.016
CVE-2020-1603
Junos OS: Improper handling of specific IPv6 packets sent by clients eventually kernel crash (vmcore) the device.
Published 2020-01-15 · Modified
8.6EPSS 0.014
CVE-2020-1613
Junos OS: BGP session termination upon receipt of specific BGP FlowSpec advertisement.
Published 2020-04-08 · Modified
8.6EPSS 0.013
CVE-2021-0251
Junos OS: MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC: The BRAS Subscriber Services service activation portal is vulnerable to a Denial of Service (DoS) via malformed HTTP packets
Published 2021-04-22 · Modified
8.6EPSS 0.011
CVE-2020-1632
Junos OS and Junos OS Evolved: Invalid BGP UPDATE sent to peer device may cause BGP session to terminate.
Published 2020-04-15 · Modified
8.6EPSS 0.011
CVE-2021-0203
Junos OS: EX and QFX5K Series: Storm Control does not work as expected when Redundant Trunk Group is configured
Published 2021-01-15 · Modified
8.6EPSS 0.010
CVE-2019-0041
Junos OS: EX4300-MP Series: IP transit traffic can reach the control plane via loopback interface.
Published 2019-04-10 · Modified
8.6EPSS 0.009
CVE-2025-52983
Junos OS: After removing ssh public key authentication root can still log in
Published 2025-07-11 · Analyzed
8.6EPSS 0.006
CVE-2013-6012
Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to bypass authentication via unspecified vectors.
Published 2013-10-28 · Modified
8.5EPSS 0.022
CVE-2025-30661
Junos OS: Low-privileged user can cause script to run as root, leading to privilege escalation
Published 2025-07-11 · Analyzed
8.5EPSS 0.002
CVE-2026-33793
Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system
Published 2026-04-09 · Analyzed
8.5EPSS 0.002
CVE-2026-33791
Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root
Published 2026-04-09 · Modified
8.4EPSS 0.007
CVE-2025-52988
Junos OS and Junos OS Evolved: Privilege escalation to root via CLI command 'request system logout'
Published 2025-07-11 · Analyzed
8.4EPSS 0.005
CVE-2016-4922
Junos: Privilege escalation vulnerabilities in Junos CLI
Published 2017-10-13 · Modified
8.4EPSS 0.005
CVE-2016-4924
vMX: Information leak vulnerability
Published 2017-10-13 · Modified
8.4EPSS 0.003
CVE-2023-44194
Junos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privileges
Published 2023-10-12 · Modified
8.4EPSS 0.002
CVE-2025-30650
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
Published 2026-04-08 · Analyzed
8.4EPSS 0.001
CVE-2020-1667
Junos OS: MX Series: Services card might restart due to a race condition when DNS filtering is enabled.
Published 2020-10-16 · Modified
8.3EPSS 0.007
CVE-2020-1645
Junos OS: MX Series: Services card might restart when DNS filtering is enabled
Published 2020-07-17 · Modified
8.3EPSS 0.006
CVE-2026-33779
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
Published 2026-04-09 · Analyzed
8.3EPSS 0.002
CVE-2018-0002
MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.
Published 2018-01-10 · Modified
8.2EPSS 0.015
CVE-2025-21598
Junos OS and Junos OS Evolved: When BGP traceoptions are configured, receipt of malformed BGP packets causes RPD to crash
Published 2025-01-09 · Analyzed
8.2EPSS 0.007
CVE-2024-47491
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP path attribute leads to an RPD crash
Published 2024-10-11 · Analyzed
8.2EPSS 0.006
CVE-2024-30401
Junos OS: MX Series and EX9200-15C: Stack-based buffer overflow in aftman
Published 2024-04-12 · Analyzed
8.2EPSS 0.006
CVE-2024-30402
Junos OS and Junos OS Evolved: The l2ald crashes on receiving telemetry messages from a specific subscription
Published 2024-04-12 · Analyzed
8.2EPSS 0.005
CVE-2025-52948
Junos OS: Specific unknown traffic pattern causes FPC and system to crash when packet capturing is enabled
Published 2025-07-11 · Analyzed
8.2EPSS 0.004
CVE-2025-52984
Junos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashes
Published 2025-07-11 · Analyzed
8.2EPSS 0.004
CVE-2026-57022
Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2026-57030
Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2025-52982
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash
Published 2025-07-11 · Analyzed
8.2EPSS 0.004
← Prev4 / 20Next →