VendorsJuniperjunos18.4
Vulnerabilities

Juniper Junos 18.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

199CVEs
CVE-2021-0246
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3: In a multi-tenant environment, a tenant host administrator may be able to jailbreak out of their network impacting other tenant networks or gather information from other networks.
Published 2021-04-22 · Modified
7.3EPSS 0.002
CVE-2020-1637
Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
Published 2020-04-08 · Modified
7.2EPSS 0.008
CVE-2021-31375
Junos OS: Receipt of a specific BGP update may cause RPKI policy-checks to be bypassed
Published 2021-10-19 · Modified
7.2EPSS 0.008
CVE-2021-0219
Junos OS: Command injection vulnerability in 'request system software' CLI command
Published 2021-01-15 · Modified
7.2EPSS 0.007
CVE-2021-0258
Junos OS: Kernel panic upon receipt of specific TCPv6 packet on management interface
Published 2021-04-22 · Modified
7.1EPSS 0.006
CVE-2019-0073
Junos OS: PKI key pairs are exported with insecure file permissions
Published 2019-10-09 · Modified
7.1EPSS 0.003
CVE-2021-31360
Junos OS and Junos OS Evolved: Denial of Service vulnerability in local file processing
Published 2021-10-19 · Modified
7.1EPSS 0.002
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2020-1600
Junos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.
Published 2020-01-15 · Modified
6.8EPSS 0.012
CVE-2021-0210
Junos OS: Privilege escalation in J-Web due to arbitrary command and code execution via information disclosure from another users active session
Published 2021-01-15 · Modified
6.8EPSS 0.011
CVE-2021-0236
Junos OS: A specific BGP VPNv6 flowspec message causes routing protocol daemon (rpd) process to crash with a core.
Published 2021-04-22 · Modified
6.8EPSS 0.008
CVE-2021-0247
Junos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration.
Published 2021-04-22 · Modified
6.8EPSS 0.006
CVE-2022-22154
Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
Published 2022-01-19 · Modified
6.8EPSS 0.002
CVE-2020-1619
Junos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulnerability in NG-RE.
Published 2020-04-08 · Modified
6.7EPSS 0.003
CVE-2021-0291
Junos OS and Junos OS Evolved: A vulnerability allows a network based unauthenticated attacker which sends a high rate of specific traffic to cause a partial Denial of Service
Published 2021-07-15 · Modified
6.5EPSS 0.010
CVE-2020-1625
Junos OS: Kernel memory leak in virtual-memory due to interface flaps
Published 2020-04-08 · Modified
6.5EPSS 0.008
CVE-2021-0215
Junos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flaps
Published 2021-01-15 · Modified
6.5EPSS 0.008
CVE-2020-1670
Junos OS: EX4300 Series: High CPU load due to receipt of specific IPv4 packets
Published 2020-10-16 · Modified
6.5EPSS 0.005
CVE-2020-1668
Junos OS: EX2300 Series: High CPU load due to receipt of specific multicast packets on layer 2 interface
Published 2020-10-16 · Modified
6.5EPSS 0.005
CVE-2021-0221
Junos OS: QFX Series: Traffic loop Denial of Service (DoS) upon receipt of specific IP multicast traffic
Published 2021-01-15 · Modified
6.5EPSS 0.005
CVE-2020-1689
Junos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames when deployed in a Virtual Chassis configuration
Published 2020-10-16 · Modified
6.5EPSS 0.005
CVE-2020-1687
Junos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames in EVPN-VXLAN deployment.
Published 2020-10-16 · Modified
6.5EPSS 0.005
CVE-2021-0214
Junos OS: Denial of Service in ppmd upon receipt of malformed packet
Published 2021-04-22 · Modified
6.5EPSS 0.005
CVE-2021-0272
Junos OS: QFX10002-32Q, QFX10002-60C, QFX10002-72Q, QFX10008, QFX10016: In EVPN-VXLAN scenarios receipt of specific genuine packets by an adjacent attacker will cause a kernel memory leak in FPC.
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-31362
Junos OS and Junos OS Evolved: An IS-IS adjacency might be taken down if a bad hello PDU is received for an existing adjacency causing a DoS
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-31370
Junos OS: QFX5000 Series and EX4600 Series: Control traffic might be dropped if a high rate of specific multicast traffic is received
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-31366
Junos OS: MX Series: In subscriber management / BBE configuration authd can crash if a subscriber with a specific username tries to login leading to a DoS
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-0216
Junos OS: ACX5448, ACX710: BFD sessions might flap due to high rate of transit ARP packets
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0228
Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0242
Junos OS: EX4300: FPC crash upon receipt of specific frames on an interface without L2PT or dot1x configured
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0257
Junos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interface
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-31365
Junos OS: EX2300, EX3400 and EX4300 Series: An Aggregated Ethernet (AE) interface will go down due to a stream of specific layer 2 frames
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-31367
Junos OS: PTX Series: An FPC heap memory leak will be triggered by certain Flowspec route operations which can lead to an FPC crash
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2020-1641
Junos OS: A race condition on receipt of crafted LLDP packets leads to a memory leak and an LLDP crash.
Published 2020-07-17 · Modified
6.5EPSS 0.004
CVE-2021-0288
Junos OS: MX Series, EX9200 Series: FPC may crash upon receipt of specific MPLS packet affecting Trio-based MPCs
Published 2021-07-15 · Modified
6.5EPSS 0.004
CVE-2021-0290
Junos OS: MX Series, EX9200 Series, SRX4600: Ethernet interface vulnerable to specially crafted frames
Published 2021-07-15 · Modified
6.5EPSS 0.004
CVE-2021-0224
Junos OS: ANCPD core when hitting maximum-discovery-table-entries limit
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0237
Junos OS: EX4300-MP/EX4600/EX4650/QFX5K Series: Packet Forwarding Engine manager (FXPC) process crashes when deployed in a Virtual Chassis (VC) configuration
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2022-22179
Junos OS: jdhcpd crashes upon receiving a specific DHCP packet
Published 2022-01-19 · Modified
6.5EPSS 0.004
CVE-2022-22191
Junos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP traffic
Published 2022-04-14 · Modified
6.5EPSS 0.004
← Prev4 / 5Next →