VendorsJuniperjunos15.1
Vulnerabilities

Juniper Junos 15.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

161CVEs
CVE-2018-0056
MX Series: L2ALD daemon may crash if a duplicate MAC is learned by two different interfaces
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2018-0055
Junos OS: jdhcpd process crash during processing of specially crafted DHCPv6 message
Published 2018-10-10 · Modified
6.5EPSS 0.006
CVE-2018-0029
Junos OS: Kernel crash (vmcore) during broadcast storm after enabling 'monitor traffic interface fxp0'
Published 2018-07-11 · Modified
6.5EPSS 0.006
CVE-2022-22249
Junos OS: MX Series: An FPC crash might be seen due to mac-moves within the same bridge domain
Published 2022-10-18 · Modified
6.5EPSS 0.005
CVE-2021-31366
Junos OS: MX Series: In subscriber management / BBE configuration authd can crash if a subscriber with a specific username tries to login leading to a DoS
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-0271
Junos OS: EX2200-C Series, EX3200 Series, EX3300 Series, EX4200 Series, EX4500 Series, EX4550 Series, EX6210 Series, EX8208 Series, EX8216 Series: Receipt of a crafted ARP packet by an adjacent attacker will cause the sfid process to core.
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0228
Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-31365
Junos OS: EX2300, EX3400 and EX4300 Series: An Aggregated Ethernet (AE) interface will go down due to a stream of specific layer 2 frames
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2020-1641
Junos OS: A race condition on receipt of crafted LLDP packets leads to a memory leak and an LLDP crash.
Published 2020-07-17 · Modified
6.5EPSS 0.004
CVE-2021-0237
Junos OS: EX4300-MP/EX4600/EX4650/QFX5K Series: Packet Forwarding Engine manager (FXPC) process crashes when deployed in a Virtual Chassis (VC) configuration
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2022-22191
Junos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP traffic
Published 2022-04-14 · Modified
6.5EPSS 0.004
CVE-2022-22214
Junos OS and Junos OS Evolved: In an MPLS scenario upon receipt of a specific IPv6 packet an FPC will crash
Published 2022-07-20 · Modified
6.5EPSS 0.003
CVE-2018-0034
Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
Published 2018-07-11 · Modified
5.9EPSS 0.021
CVE-2016-1257
The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1R3-S9, 14.1R4 before 14.1R4-S7, 14.1X51 before 14.1X51-D65, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D28, 14.1X53 before 4.1X53-D35, 14.2R1 before 14.2R5, 14.2R3 before 14.2R3-S4, 14.2R4 before 14.2R4-S1, 15.1 before 15.1R3, 15.1F2 before 15.1F2-S2, and 15.1X49 before 15.1X49-D40, when LDP is enabled, allows remote attackers to cause a denial of service (RPD routing process crash) via a crafted LDP packet.
Published 2016-01-15 · Modified
5.9EPSS 0.015
CVE-2017-10618
Junos: RPD core due to BGP UPDATE with malformed optional transitive attributes
Published 2017-10-13 · Modified
5.9EPSS 0.015
CVE-2018-0019
Junos: Denial of service vulnerability in SNMP MIB-II subagent daemon (mib2d).
Published 2018-04-11 · Modified
5.9EPSS 0.015
CVE-2018-0031
Junos OS: Receipt of specially crafted UDP packets over MPLS may bypass stateless IP firewall rules
Published 2018-07-11 · Modified
5.9EPSS 0.012
CVE-2017-2346
MS-MPC or MS-MIC crash when passing large fragmented traffic through an ALG
Published 2017-07-14 · Modified
5.9EPSS 0.011
CVE-2018-0060
Junos OS: Invalid IP/mask learned from DHCP server might cause device control daemon (dcd) process crash
Published 2018-10-10 · Modified
5.9EPSS 0.011
CVE-2022-22169
Junos OS and Junos OS Evolved: OSPFv3 session might go into INIT state upon receipt of multiple crafted packets from a trusted neighbor device.
Published 2022-01-19 · Modified
5.9EPSS 0.008
CVE-2021-31386
Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.
Published 2021-10-19 · Modified
5.9EPSS 0.007
CVE-2016-1273
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
Published 2016-04-15 · Modified
5.9EPSS 0.007
CVE-2019-0069
Junos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear text
Published 2019-10-09 · Modified
5.9EPSS 0.002
CVE-2019-0074
Junos OS: NFX150 Series, QFX10K Series, EX9200 Series, MX Series, PTX Series: Path traversal vulnerability in NFX150 and NG-RE leads to information disclosure.
Published 2019-10-09 · Modified
5.5EPSS 0.004
CVE-2020-1643
Junos OS: EX Series: RPD crash when executing specific "show ospf interface" commands from the CLI with OSPF authentication configured
Published 2020-07-17 · Modified
5.5EPSS 0.003
CVE-2017-10613
Junos OS: A kernel hang may occur due to a specific loopback filter action command
Published 2017-10-13 · Modified
5.5EPSS 0.003
CVE-2020-1630
Junos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.
Published 2020-04-08 · Modified
5.5EPSS 0.002
CVE-2021-31377
Junos OS: A local authenticated attacker can cause RPD to core
Published 2021-10-19 · Modified
5.5EPSS 0.002
CVE-2023-22398
Junos OS and Junos OS Evolved: RPD might crash when MPLS ping is performed on BGP LSPs
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2018-0061
Junos OS: Denial of service in telnetd
Published 2018-10-10 · Modified
5.3EPSS 0.023
CVE-2017-2340
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and destined to M/MX series routers can result in a PFE (Packet Forwarding Engine) hang or crash.
Published 2017-04-24 · Modified
5.3EPSS 0.022
CVE-2017-10621
Junos OS: Denial of service vulnerability in telnetd
Published 2017-10-13 · Modified
5.3EPSS 0.018
CVE-2016-1256
Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R7, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D18 or 14.1X53-D30, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R4, 15.1 before 15.1R2, and 15.1X49 before 15.1X49-D10 allow remote attackers to cause a denial of service via a malformed IGMPv3 packet, aka a "multicast denial of service."
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2020-1680
Junos OS: MX Series: MS-MPC/MIC might crash when processing malformed IPv6 packet in NAT64 configuration.
Published 2020-10-16 · Modified
5.3EPSS 0.013
CVE-2020-1628
Junos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces
Published 2020-04-08 · Modified
5.3EPSS 0.013
CVE-2019-0005
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet filtering is unaffected by this vulnerability. Affected releases are Juniper Networks Junos OS on EX and QFX series;: 14.1X53 versions prior to 14.1X53-D47; 15.1 versions prior to 15.1R7; 15.1X53 versions prior to 15.1X53-D234 on QFX5200/QFX5110 series; 15.1X53 versions prior to 15.1X53-D591 on EX2300/EX3400 series; 16.1 versions prior to 16.1R7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R2.
Published 2019-01-15 · Modified
5.3EPSS 0.012
CVE-2021-0273
Junos OS and Junos OS Evolved: Trio Chipset: Denial of Service due to packet destined to device's interfaces.
Published 2021-04-22 · Modified
5.3EPSS 0.010
CVE-2020-1661
Junos OS: jdhcpd process crash when forwarding a malformed DHCP packet.
Published 2020-10-16 · Modified
5.3EPSS 0.010
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562
CVE-2015-7748
Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R2 allow remote attackers to cause a denial of service (MPC line card crash) via a crafted uBFD packet.
Published 2015-10-19 · Modified
5.0EPSS 0.028
← Prev4 / 5Next →