VendorsJuniperjunosany version
Vulnerabilities

Juniper Junos any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

278CVEs
CVE-2024-39517
Junos OS and Junos OS Evolved: Upon processing specific L2 traffic, rpd can hang in devices with EVPN/VXLAN configured
Published 2024-07-10 · Analyzed
7.1EPSS 0.002
CVE-2025-30647
Junos OS: MX Series: Subscriber login/logout activity will lead to a memory leak
Published 2025-04-09 · Analyzed
7.1EPSS 0.002
CVE-2025-30646
Junos OS and Junos OS Evolved: Receipt of a malformed LLDP TLV results in l2cpd crash
Published 2025-04-09 · Analyzed
7.1EPSS 0.002
CVE-2025-21593
Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash
Published 2025-01-09 · Analyzed
7.1EPSS 0.002
CVE-2024-30387
Junos OS: ACX5448 & ACX710: Due to interface flaps the PFE process can crash
Published 2024-04-12 · Analyzed
7.1EPSS 0.002
CVE-2024-39556
Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow
Published 2024-07-10 · Analyzed
7.1EPSS 0.001
CVE-2025-59957
Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor
Published 2025-10-09 · Analyzed
7.0EPSS 0.002
CVE-2025-60011
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap
Published 2026-01-15 · Analyzed
6.9EPSS 0.005
CVE-2026-57024
Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2025-30657
Junos OS: Processing of a specific BGP update causes the SRRD process to crash
Published 2025-04-09 · Analyzed
6.9EPSS 0.004
CVE-2026-57054
Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2024-30410
Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.
Published 2024-04-12 · Analyzed
6.9EPSS 0.004
CVE-2015-7751
Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D105, 14.1X51 before 14.1X51-D70, 14.1X53 before 14.1X53-D25, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R1, 15.1 before 15.1F2 or 15.1R1, and 15.1X49 before 15.1X49-D10 does not require a password for the root user when pam.conf is "corrupted," which allows local users to gain root privileges by modifying the file.
Published 2015-10-19 · Modified
6.9EPSS 0.004
CVE-2025-52951
Junos OS: IPv6 firewall filter fails to match payload-protocol
Published 2025-07-11 · Analyzed
6.9EPSS 0.003
CVE-2024-39561
Junos OS: SRX4600, SRX5000 Series: TCP packets with SYN/FIN or SYN/RST are transferred after enabling no-syn-check with Express Path
Published 2024-07-10 · Analyzed
6.9EPSS 0.003
CVE-2024-39533
Junos OS: QFX5000 Series and EX4600 Series: Output firewall filter is not applied if certain match criteria are used
Published 2024-07-11 · Analyzed
6.9EPSS 0.003
CVE-2025-59980
Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed
Published 2025-10-09 · Analyzed
6.9EPSS 0.003
CVE-2024-47507
Junos OS and Junos OS Evolved: BGP update message containing aggregator attribute with an ASN value of zero (0) is accepted
Published 2024-10-11 · Analyzed
6.9EPSS 0.003
CVE-2026-33774
Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
Published 2026-04-09 · Analyzed
6.9EPSS 0.003
CVE-2025-6549
Junos OS: SRX Series: J-Web can be exposed on additional interfaces
Published 2025-07-11 · Analyzed
6.9EPSS 0.002
CVE-2024-30378
Junos OS: MX Series: bbe-smgd process crash upon execution of specific CLI commands
Published 2024-04-16 · Analyzed
6.9EPSS 0.002
CVE-2013-6013
Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 12.1X45-D10 on SRX devices, when using telnet pass-through authentication on the firewall, might allow remote attackers to execute arbitrary code via a crafted telnet message.
Published 2013-10-17 · Modified
6.8EPSS 0.040
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2024-39527
Junos OS: SRX Series: Low privileged user able to access sensitive information on file system
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2024-47501
Junos OS: MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C: In a VPLS or Junos Fusion scenario specific show commands cause FPCs to crash
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2024-47496
Junos OS: MX Series: The PFE will crash on running specific command
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2025-30654
Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information
Published 2025-04-09 · Analyzed
6.8EPSS 0.002
CVE-2024-30384
Junos OS: EX4300 Series: If a specific CLI command is issued PFE crashes will occur
Published 2024-04-12 · Analyzed
6.8EPSS 0.002
CVE-2025-21592
Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system
Published 2025-01-09 · Analyzed
6.8EPSS 0.002
CVE-2025-30652
Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configured causes an rpd crash
Published 2025-04-09 · Analyzed
6.8EPSS 0.002
CVE-2025-21596
Junos OS: SRX1500,SRX4100,SRX4200: Execution of low-privileged CLI command results in chassisd crash
Published 2025-01-09 · Analyzed
6.8EPSS 0.002
CVE-2024-39511
Junos OS: The 802.1X Authentication Daemon crashes on running a specific command
Published 2024-07-10 · Analyzed
6.8EPSS 0.001
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
Published 2026-01-15 · Modified
6.8EPSS 0.001
CVE-2025-59959
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2025-30655
Junos OS and Junos OS Evolved: A specific CLI command will cause an RPD crash when rib-sharding and update-threading is enabled
Published 2025-04-09 · Analyzed
6.8EPSS 0.001
CVE-2026-57025
Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
Published 2026-07-09 · Modified
6.8EPSS 0.001
CVE-2025-52963
Junos OS: A low-privileged user can disable an interface
Published 2025-07-11 · Analyzed
6.8EPSS 0.001
CVE-2025-59961
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2026-33776
Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2025-52989
Junos OS and Junos OS Evolved: Annotate configuration command can be used to change the configuration
Published 2025-07-11 · Analyzed
6.8EPSS 0.001
← Prev5 / 7Next →