VendorsJuniperjunos15.1x49
Vulnerabilities

Juniper Junos 15.1x49

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

134CVEs
CVE-2016-1273
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
Published 2016-04-15 · Modified
5.9EPSS 0.007
CVE-2019-0069
Junos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear text
Published 2019-10-09 · Modified
5.9EPSS 0.002
CVE-2019-0015
Junos OS: SRX Series: Deleted dynamic VPN users are allowed to establish VPN connections until reboot
Published 2019-01-15 · Modified
5.5EPSS 0.008
CVE-2020-1643
Junos OS: EX Series: RPD crash when executing specific "show ospf interface" commands from the CLI with OSPF authentication configured
Published 2020-07-17 · Modified
5.5EPSS 0.003
CVE-2020-1682
Junos OS: SRX1500, vSRX, SRX4K, NFX150, NFX250: Denial of service vulnerability executing local CLI command
Published 2020-10-16 · Modified
5.5EPSS 0.003
CVE-2017-10613
Junos OS: A kernel hang may occur due to a specific loopback filter action command
Published 2017-10-13 · Modified
5.5EPSS 0.003
CVE-2020-1630
Junos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.
Published 2020-04-08 · Modified
5.5EPSS 0.002
CVE-2018-0061
Junos OS: Denial of service in telnetd
Published 2018-10-10 · Modified
5.3EPSS 0.023
CVE-2017-10621
Junos OS: Denial of service vulnerability in telnetd
Published 2017-10-13 · Modified
5.3EPSS 0.018
CVE-2020-1628
Junos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces
Published 2020-04-08 · Modified
5.3EPSS 0.013
CVE-2020-1661
Junos OS: jdhcpd process crash when forwarding a malformed DHCP packet.
Published 2020-10-16 · Modified
5.3EPSS 0.010
CVE-2017-10604
Junos OS: SRX Series: Cluster configuration sync failures occur if the root user account is locked out
Published 2017-07-14 · Modified
5.3EPSS 0.009
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562
CVE-2015-5360
IPv6 sendd in Juniper Junos 12.1X44 before 12.1X44-D51, 12.1X46 before 12.1X46-D36, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D20, when the "set protocols neighbor-discovery secure security-level default" option is configured, allows remote attackers to cause a denial of service (CPU consumption) via a crafted Secure Neighbor Discovery (SEND) Protocol packet.
Published 2015-07-16 · Modified
5.0EPSS 0.018
← Prev4 / 4