VendorsJuniperjunos21.1
Vulnerabilities

Juniper Junos 21.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

161CVEs
CVE-2023-44203
Junos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2021-0289
Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted
Published 2021-07-15 · Modified
6.5EPSS 0.003
CVE-2024-30391
Junos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performed
Published 2024-04-12 · Analyzed
6.3EPSS 0.004
CVE-2022-22242
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
Published 2022-10-18 · Modified
6.1EPSS 0.028
CVE-2022-22169
Junos OS and Junos OS Evolved: OSPFv3 session might go into INIT state upon receipt of multiple crafted packets from a trusted neighbor device.
Published 2022-01-19 · Modified
5.9EPSS 0.008
CVE-2021-31386
Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.
Published 2021-10-19 · Modified
5.9EPSS 0.007
CVE-2022-22213
Junos OS and Junos OS Evolved: Denial of Service (DoS) vulnerability in RPD upon receipt of specific BGP update
Published 2022-07-20 · Modified
5.9EPSS 0.007
CVE-2022-22220
Junos OS and Junos OS Evolved: Due to a race condition the rpd process can crash upon receipt of a BGP update message containing flow spec route
Published 2022-10-18 · Modified
5.9EPSS 0.005
CVE-2022-22225
Junos OS and Junos OS Evolved: In a BGP multipath scenario, when one of the contributing routes is flapping often and rapidly, rpd may crash
Published 2022-10-18 · Modified
5.9EPSS 0.005
CVE-2022-22208
Junos OS and Junos OS Evolved: An rpd crash can occur due to memory corruption caused by flapping BGP sessions
Published 2022-10-18 · Modified
5.9EPSS 0.005
CVE-2023-28961
Junos OS: ACX Series: IPv6 firewall filter is not installed in PFE when "from next-header ah" is used
Published 2023-04-17 · Modified
5.8EPSS 0.004
CVE-2022-22193
Junos OS and Junos OS Evolved: In a BGP rib-sharding scenario when a certain CLI command is executed the rpd process might crash
Published 2022-04-14 · Modified
5.5EPSS 0.002
CVE-2022-22240
Junos OS and Junos OS Evolved: An rpd memory leak might be observed while running a specific cli command in a RIB sharding scenario
Published 2022-10-18 · Modified
5.5EPSS 0.002
CVE-2023-36840
Junos OS and Junos OS Evolved: An rpd crash occurs when a specific L2VPN command is run
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2022-22234
Junos OS: EX2300 and EX3400 Series: One of more SFPs might become unavailable when the system is very busy
Published 2022-10-18 · Modified
5.5EPSS 0.002
CVE-2023-22409
Junos OS: SRX Series, MX Series with SPC3: When an inconsistent NAT configuration exists and a specific CLI command is issued the SPC will reboot
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2024-21594
Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash
Published 2024-01-12 · Modified
5.5EPSS 0.002
CVE-2023-28980
Junos OS and Junos OS Evolved: In a BGP rib sharding scenario an rpd crash will happen shortly after a specific CLI command is issued
Published 2023-04-17 · Modified
5.5EPSS 0.002
CVE-2023-22398
Junos OS and Junos OS Evolved: RPD might crash when MPLS ping is performed on BGP LSPs
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2023-44193
Junos OS: MX Series: An FPC crash is observed when CFM is enabled in a VPLS scenario and a specific LDP related command is run
Published 2023-10-12 · Modified
5.5EPSS 0.002
CVE-2023-44201
Junos OS and Junos OS Evolved: A local attacker can retrieve sensitive information and elevate privileges on the device to an authorized user.
Published 2023-10-12 · Modified
5.5EPSS 0.001
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.835
CVE-2021-31361
Junos OS: QFX Series and PTX Series: FPC resource usage increases when certain packets are processed which are being VXLAN encapsulated
Published 2021-10-19 · Modified
5.3EPSS 0.010
CVE-2021-31369
Junos OS: MX Series: Traffic drops will be observed if MS-MPC/MS-PIC resources are consumed by certain traffic causing a partial DoS
Published 2021-10-19 · Modified
5.3EPSS 0.010
CVE-2021-31371
Junos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces.
Published 2021-10-19 · Modified
5.3EPSS 0.008
CVE-2022-22204
Junos OS: MX Series and SRX Series: When receiving a specific SIP packets stale call table entries are created which eventually leads to a DoS for all SIP traffic
Published 2022-07-20 · Modified
5.3EPSS 0.007
CVE-2023-28968
Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open
Published 2023-04-17 · Modified
5.3EPSS 0.006
CVE-2022-22244
Junos OS: Unauthenticated XPath Injection vulnerability in J-Web
Published 2022-10-18 · Modified
5.3EPSS 0.005
CVE-2023-28963
Junos OS: User-controlled input vulnerability in J-Web
Published 2023-04-17 · Modified
5.3EPSS 0.005
CVE-2023-44188
Junos OS: jkdsd crash due to multiple telemetry requests
Published 2023-10-11 · Modified
5.3EPSS 0.003
CVE-2024-21607
Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected
Published 2024-01-12 · Modified
5.3EPSS 0.003
CVE-2023-28984
Junos OS: QFX Series: The PFE may crash when a lot of MAC addresses are being learned and aged
Published 2023-04-17 · Modified
5.3EPSS 0.002
CVE-2023-28979
Junos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check fails
Published 2023-04-17 · Modified
4.7EPSS 0.003
CVE-2023-36836
Junos OS and Junos OS Evolved: In a MoFRR scenario an rpd core may be observed when a low privileged CLI command is executed
Published 2023-07-14 · Modified
4.7EPSS 0.002
CVE-2023-28975
Junos OS: The kernel will crash when certain USB devices are inserted
Published 2023-04-17 · Modified
4.6EPSS 0.003
CVE-2022-22245
Junos OS: Path traversal vulnerability in J-Web
Published 2022-10-18 · Modified
4.3EPSS 0.007
CVE-2022-22243
Junos OS: XPath Injection vulnerability in J-Web
Published 2022-10-18 · Modified
4.3EPSS 0.005
← Prev4 / 5Next →