VendorsJuniperjunos12.3x48
Vulnerabilities

Juniper Junos 12.3x48

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

113CVEs
CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Published 2020-03-06 · Modified
10.0EPSS 0.743
CVE-2016-1279
J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1, 14.1 before 14.1R7, 14.1X53 before 14.1X53-D35, 14.2 before 14.2R6, 15.1 before 15.1A2 or 15.1F4, 15.1X49 before 15.1X49-D30, and 15.1R before 15.1R3 might allow remote attackers to obtain sensitive information and consequently gain administrative privileges via unspecified vectors.
Published 2016-09-09 · Modified
10.0EPSS 0.029
CVE-2017-2343
SRX Series: Hardcoded credentials in Integrated UserFW feature.
Published 2017-07-14 · Modified
10.0EPSS 0.027
CVE-2018-0007
An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to occur, leading to a denial of service. Further crafted packets may be able to sustain the denial of service condition. Score: 6.5 MEDIUM (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Further, if the attacker is authenticated on the target device receiving and processing the malicious LLDP packet, while receiving the crafted packets, the attacker may be able to perform command or arbitrary code injection over the target device thereby elevating their permissions and privileges, and taking control of the device. Score: 7.8 HIGH (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to one or more local segments, via LLDP proxy / tunneling agents or other LLDP through Layer 3 deployments, through one or more local segment broadcasts, may be able to cause multiple Junos devices to enter an improper boundary check condition allowing a memory corruption to occur, leading to multiple distributed Denials of Services. These Denials of Services attacks may have cascading Denials of Services to adjacent connected devices, impacts network devices, servers, workstations, etc. Further crafted packets may be able to sustain these Denials of Services conditions. Score 6.8 MEDIUM (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H) Further, if the attacker is authenticated on one or more target devices receiving and processing these malicious LLDP packets, while receiving the crafted packets, the attacker may be able to perform command or arbitrary code injection over multiple target devices thereby elevating their permissions and privileges, and taking control multiple devices. Score: 7.8 HIGH (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71; 12.3 versions prior to 12.3R12-S7; 12.3X48 versions prior to 12.3X48-D55; 14.1 versions prior to 14.1R8-S5, 14.1R9; 14.1X53 versions prior to 14.1X53-D46, 14.1X53-D50, 14.1X53-D107; 14.2 versions prior to 14.2R7-S9, 14.2R8; 15.1 versions prior to 15.1F2-S17, 15.1F5-S8, 15.1F6-S8, 15.1R5-S7, 15.1R7; 15.1X49 versions prior to 15.1X49-D90; 15.1X53 versions prior to 15.1X53-D65; 16.1 versions prior to 16.1R4-S6, 16.1R5; 16.1X65 versions prior to 16.1X65-D45; 16.2 versions prior to 16.2R2; 17.1 versions prior to 17.1R2. No other Juniper Networks products or platforms are affected by this issue.
Published 2018-01-10 · Modified
10.0EPSS 0.022
CVE-2017-10601
Junos OS: Insufficient authentication for user login when a specific system configuration error occurs.
Published 2017-07-14 · Modified
10.0EPSS 0.018
CVE-2017-2349
SRX Series: Command injection vulnerability in SRX IDP feature.
Published 2017-07-14 · Modified
9.9EPSS 0.023
CVE-2018-0001
Junos: Unauthenticated Remote Code Execution through J-Web interface
Published 2018-01-10 · Modified
9.8EPSS 0.063
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-05-04 · Analyzed
9.8KEVEPSS 0.048
CVE-2017-2345
Junos: snmpd denial of service upon receipt of crafted SNMP packet
Published 2017-07-14 · Modified
9.8EPSS 0.036
CVE-2018-0052
Junos OS: Unauthenticated remote root access possible when RSH service is enabled
Published 2018-10-10 · Modified
9.3EPSS 0.049
CVE-2015-5362
The BFD daemon in Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D85, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D10 allows remote attackers to cause a denial of service (bfdd crash and restart) or execute arbitrary code via a crafted BFD packet.
Published 2015-07-14 · Modified
9.3EPSS 0.038
CVE-2021-0275
Junos OS: J-Web: Cross-site scripting attack allows an attacker to gain control of another users session.
Published 2021-04-22 · Modified
9.3EPSS 0.012
CVE-2016-1264
Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before 13.2X52-D30, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4, 15.1 before 15.1F2 or 15.1R2, 15.1X49 before 15.1X49-D10 or 15.1X49-D20, and 16.1 before 16.1R1 allows remote authenticated users to gain privileges via the URL option.
Published 2016-04-15 · Modified
8.8EPSS 0.017
CVE-2019-0047
Junos OS: Persistent XSS vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.016
CVE-2018-0043
Junos OS: RPD daemon crashes upon receipt of specific MPLS packet
Published 2018-10-10 · Modified
8.8EPSS 0.012
CVE-2018-0045
Junos OS: RPD daemon crashes due to receipt of specific Draft-Rosen MVPN control packet in Draft-Rosen MVPN configuration
Published 2018-10-10 · Modified
8.8EPSS 0.011
CVE-2020-1656
Junos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.
Published 2020-10-16 · Modified
8.8EPSS 0.011
CVE-2019-0062
Junos OS: Session fixation vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.011
CVE-2016-1261
Junos: vulnerabilities in J-Web (CVE-2016-1261)
Published 2017-10-13 · Modified
8.8EPSS 0.004
CVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Published 2016-03-09 · Modified
8.6EPSS 0.621
CVE-2017-10605
Junos: SRX Series denial of service vulnerability in flowd due to crafted DHCP packet
Published 2017-07-14 · Modified
8.6EPSS 0.016
CVE-2020-1613
Junos OS: BGP session termination upon receipt of specific BGP FlowSpec advertisement.
Published 2020-04-08 · Modified
8.6EPSS 0.013
CVE-2016-4922
Junos: Privilege escalation vulnerabilities in Junos CLI
Published 2017-10-13 · Modified
8.4EPSS 0.005
CVE-2018-0002
MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.
Published 2018-01-10 · Modified
8.2EPSS 0.015
CVE-2018-0025
Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication
Published 2018-07-11 · Modified
8.1EPSS 0.014
CVE-2020-1606
Junos OS: Path traversal vulnerability in J-Web
Published 2020-01-15 · Modified
8.1EPSS 0.009
CVE-2016-4923
Junos J-Web: Cross Site Scripting Vulnerability
Published 2017-10-13 · Modified
8.0EPSS 0.010
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2016-4921
Junos: IPv6 denial of service vulnerability due to resource exhaustion (CVE-2016-4921)
Published 2017-10-13 · Modified
7.8EPSS 0.029
CVE-2018-0022
Junos OS: Mbuf leak due to processing MPLS packets in VPLS network.
Published 2018-04-11 · Modified
7.8EPSS 0.022
CVE-2017-2301
On Juniper Networks products or platforms running Junos OS 11.4 prior to 11.4R13-S3, 12.1X46 prior to 12.1X46-D60, 12.3 prior to 12.3R12-S2 or 12.3R13, 12.3X48 prior to 12.3X48-D40, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D12 or 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R7, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D60, 15.1X53 prior to 15.1X53-D30 and DHCPv6 enabled, when a crafted DHCPv6 packet is received from a subscriber, jdhcpd daemon crashes and restarts. Repeated crashes of the jdhcpd process may constitute an extended denial of service condition for subscribers attempting to obtain IPv6 addresses.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2017-2302
On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D55, 12.1X47 prior to 12.1X47-D45, 12.3R13 prior to 12.3R13, 12.3X48 prior to 12.3X48-D35, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D40, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R6, 15.1 prior to 15.1F2 or 15.1R1, 15.1X49 prior to 15.1X49-D20 where the BGP add-path feature is enabled with 'send' option or with both 'send' and 'receive' options, a network based attacker can cause the Junos OS rpd daemon to crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2017-2303
On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D50, 12.1X47 prior to 12.1X47-D40, 12.3 prior to 12.3R13, 12.3X48 prior to 12.3X48-D30, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R5, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D30 or 15.1X49-D40, 15.1X53 prior to 15.1X53-D35, and where RIP is enabled, certain RIP advertisements received by the router may cause the RPD daemon to crash resulting in a denial of service condition.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2014-6450
Juniper Junos OS before 11.4R12-S4, 12.1X44 before 12.1X44-D41, 12.1X46 before 12.1X46-D26, 12.1X47 before 12.1X47-D11/D15, 12.2 before 12.2R9, 12.2X50 before 12.2X50-D70, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 12.3X50 before 12.3X50-D42, 13.1 before 13.1R4-S3, 13.1X49 before 13.1X49-D42, 13.1X50 before 13.1X50-D30, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D26, 13.2X52 before 13.2X52-D15, 13.3 before 13.3R3-S3, 14.1 before 14.1R3, 14.2 before 14.2R1, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D10, when configured for IPv6, allow remote attackers to cause a denial of service (mbuf chain corruption and kernel panic) via crafted IPv6 packets.
Published 2015-10-16 · Modified
7.8EPSS 0.019
CVE-2015-7752
The SSH server in Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D25, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D20 allows remote attackers to cause a denial of service (CPU consumption) via unspecified SSH traffic.
Published 2015-10-19 · Modified
7.8EPSS 0.019
CVE-2016-1269
Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps.
Published 2016-04-15 · Modified
7.8EPSS 0.019
CVE-2019-0052
SRX Series: srxpfe process crash while JSF/UTM module parses specific HTTP packets
Published 2019-07-11 · Modified
7.8EPSS 0.018
CVE-2016-1263
Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, 14.2 before 14.2R6, 15.1 before 15.1F2-S5, 15.1F4 before 15.1F4-S2, 15.1R before 15.1R2-S3, 15.1 before 15.1R3, and 15.1X49 before 15.1X49-D40 allow remote attackers to cause a denial of service (kernel crash) via a crafted UDP packet destined to the interface IP address of a 64-bit OS device.
Published 2016-09-09 · Modified
7.8EPSS 0.014
CVE-2019-0053
Junos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflow
Published 2019-07-11 · Modified
7.8EPSS 0.006
CVE-2017-2344
Junos: Buffer overflow in sockets library
Published 2017-07-14 · Modified
7.8EPSS 0.005
1 / 3Next →