VendorsJuniperjunos17.2
Vulnerabilities

Juniper Junos 17.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

104CVEs
CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Published 2020-03-06 · Modified
10.0EPSS 0.743
CVE-2020-1615
Junos OS: vMX: Default credentials supplied in vMX configuration
Published 2020-04-08 · Modified
10.0EPSS 0.018
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-05-04 · Analyzed
9.8KEVEPSS 0.048
CVE-2017-2345
Junos: snmpd denial of service upon receipt of crafted SNMP packet
Published 2017-07-14 · Modified
9.8EPSS 0.036
CVE-2019-0036
Junos OS: Firewall filter terms named "internal-1" and "internal-2" being ignored
Published 2019-04-10 · Modified
9.8EPSS 0.010
CVE-2018-0057
Junos OS: authd allows assignment of IP address requested by DHCP subscriber logging in with Option 50 (Requested IP Address)
Published 2018-10-10 · Modified
9.6EPSS 0.011
CVE-2018-0052
Junos OS: Unauthenticated remote root access possible when RSH service is enabled
Published 2018-10-10 · Modified
9.3EPSS 0.049
CVE-2021-0275
Junos OS: J-Web: Cross-site scripting attack allows an attacker to gain control of another users session.
Published 2021-04-22 · Modified
9.3EPSS 0.012
CVE-2019-0040
Junos OS: Specially crafted packets sent to port 111 on any interface triggers responses from the management interface
Published 2019-04-10 · Modified
9.1EPSS 0.019
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2019-0047
Junos OS: Persistent XSS vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.016
CVE-2018-0045
Junos OS: RPD daemon crashes due to receipt of specific Draft-Rosen MVPN control packet in Draft-Rosen MVPN configuration
Published 2018-10-10 · Modified
8.8EPSS 0.011
CVE-2020-1656
Junos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.
Published 2020-10-16 · Modified
8.8EPSS 0.011
CVE-2019-0062
Junos OS: Session fixation vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.011
CVE-2020-1609
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.009
CVE-2020-1605
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2020-1602
Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets may take over the code execution of the JDHCPD process.
Published 2020-01-15 · Modified
8.8EPSS 0.008
CVE-2020-1603
Junos OS: Improper handling of specific IPv6 packets sent by clients eventually kernel crash (vmcore) the device.
Published 2020-01-15 · Modified
8.6EPSS 0.014
CVE-2020-1613
Junos OS: BGP session termination upon receipt of specific BGP FlowSpec advertisement.
Published 2020-04-08 · Modified
8.6EPSS 0.013
CVE-2020-1632
Junos OS and Junos OS Evolved: Invalid BGP UPDATE sent to peer device may cause BGP session to terminate.
Published 2020-04-15 · Modified
8.6EPSS 0.011
CVE-2021-0203
Junos OS: EX and QFX5K Series: Storm Control does not work as expected when Redundant Trunk Group is configured
Published 2021-01-15 · Modified
8.6EPSS 0.010
CVE-2020-1606
Junos OS: Path traversal vulnerability in J-Web
Published 2020-01-15 · Modified
8.1EPSS 0.009
CVE-2018-0022
Junos OS: Mbuf leak due to processing MPLS packets in VPLS network.
Published 2018-04-11 · Modified
7.8EPSS 0.022
CVE-2018-0058
MX Series: In BBE configurations, receipt of a crafted IPv6 exception packet causes a Denial of Service
Published 2018-10-10 · Modified
7.8EPSS 0.014
CVE-2018-0020
Junos OS: rpd daemon cores due to malformed BGP UPDATE packet
Published 2018-04-11 · Modified
7.8EPSS 0.013
CVE-2020-1608
Junos OS: MX Series: In BBE configurations, receipt of a specific MPLS or IPv6 packet causes a Denial of Service
Published 2020-01-15 · Modified
7.8EPSS 0.013
CVE-2021-0283
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-07-15 · Modified
7.8EPSS 0.010
CVE-2019-0053
Junos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflow
Published 2019-07-11 · Modified
7.8EPSS 0.006
CVE-2021-0253
Junos OS: NFX Series: Local Command Execution Vulnerability in JDMD Leads to Privilege Escalation
Published 2021-04-22 · Modified
7.8EPSS 0.005
CVE-2017-2344
Junos: Buffer overflow in sockets library
Published 2017-07-14 · Modified
7.8EPSS 0.005
CVE-2019-0061
Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
Published 2019-10-09 · Modified
7.8EPSS 0.004
CVE-2021-0245
Junos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges.
Published 2021-04-22 · Modified
7.8EPSS 0.002
CVE-2019-0001
Junos OS: MX Series: uncontrolled recursion and crash in Broadband Edge subscriber management daemon (bbe-smgd).
Published 2019-01-15 · Modified
7.5EPSS 0.030
CVE-2018-0048
Junos OS: Memory exhaustion denial of service vulnerability in Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support.
Published 2018-10-10 · Modified
7.5EPSS 0.029
CVE-2018-0030
Junos OS: MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) and PTX1K: Line card may crash upon receipt of specific MPLS packet.
Published 2018-07-11 · Modified
7.5EPSS 0.024
CVE-2018-0062
Junos OS: Denial of Service in J-Web
Published 2018-10-10 · Modified
7.5EPSS 0.023
CVE-2018-15505
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Published 2018-08-18 · Modified
7.5EPSS 0.022
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2019-0013
Junos OS: RPD crash upon receipt of malformed PIM packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0012
Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message
Published 2019-01-15 · Modified
7.5EPSS 0.017
1 / 3Next →