VendorsJuniperjunos20.1
Vulnerabilities

Juniper Junos 20.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

162CVEs
CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Published 2020-03-06 · Modified
10.0EPSS 0.743
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2020-1631
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-05-04 · Analyzed
9.8KEVEPSS 0.048
CVE-2021-0254
Junos OS: Remote code execution vulnerability in overlayd service
Published 2021-04-22 · Modified
9.8EPSS 0.026
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2022-22167
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy
Published 2022-01-19 · Modified
9.8EPSS 0.007
CVE-2023-28962
Junos OS: Unauthenticated access vulnerability in J-Web
Published 2023-04-17 · Modified
9.8EPSS 0.006
CVE-2021-0268
Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
Published 2021-04-22 · Modified
9.3EPSS 0.009
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2020-1673
Junos OS: Reflected Cross-site Scripting vulnerability in J-Web and web based (HTTP/HTTPS) services
Published 2020-10-16 · Modified
8.8EPSS 0.016
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2021-0278
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-07-15 · Modified
8.8EPSS 0.009
CVE-2021-0269
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
Published 2021-04-22 · Modified
8.8EPSS 0.009
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-0277
Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
Published 2021-07-15 · Modified
8.8EPSS 0.007
CVE-2021-0208
Junos OS and Junos OS Evolved: In bidirectional LSP configurations, on MPLS egress router RPD may core upon receipt of specific malformed RSVP packet.
Published 2021-01-15 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2021-0203
Junos OS: EX and QFX5K Series: Storm Control does not work as expected when Redundant Trunk Group is configured
Published 2021-01-15 · Modified
8.6EPSS 0.010
CVE-2021-31373
Junos OS: SRX Series: Persistent XSS vulnerability in J-Web
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2022-22181
Junos OS: J-Web can be compromised through reflected XSS attacks
Published 2022-04-14 · Modified
8.0EPSS 0.007
CVE-2021-31368
Junos OS: EX2300 Series, EX3400 Series, and ACX710 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2021-10-19 · Modified
7.8EPSS 0.011
CVE-2021-0284
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-08-17 · Modified
7.8EPSS 0.010
CVE-2021-0283
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-07-15 · Modified
7.8EPSS 0.010
CVE-2021-0218
Junos OS: Command injection vulnerability in license-check daemon
Published 2021-01-15 · Modified
7.8EPSS 0.008
CVE-2020-1664
Junos OS: Buffer overflow vulnerability in device control daemon
Published 2020-10-16 · Modified
7.8EPSS 0.004
CVE-2021-0223
Junos OS: telnetd.real Local Privilege Escalation vulnerabilities in SUID binaries
Published 2021-01-15 · Modified
7.8EPSS 0.004
CVE-2021-0204
Junos OS: dexp Local Privilege Escalation vulnerabilities in SUID binaries
Published 2021-01-15 · Modified
7.8EPSS 0.003
CVE-2021-31359
Junos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
Published 2021-10-19 · Modified
7.8EPSS 0.002
CVE-2022-22162
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in
Published 2022-01-19 · Modified
7.8EPSS 0.002
CVE-2021-0245
Junos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges.
Published 2021-04-22 · Modified
7.8EPSS 0.002
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2021-0255
Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
Published 2021-04-22 · Modified
7.8EPSS 0.002
CVE-2020-1640
Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.
Published 2020-07-17 · Modified
7.5EPSS 0.014
CVE-2021-0227
Junos OS: SRX Series: Denial of Service in J-Web upon receipt of crafted HTTP packets
Published 2021-04-22 · Modified
7.5EPSS 0.013
CVE-2020-1662
Junos OS and Junos OS Evolved: RPD crash due to BGP session flapping.
Published 2020-10-16 · Modified
7.5EPSS 0.013
1 / 5Next →