VendorsJuniperjunos20.3
Vulnerabilities

Juniper Junos 20.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

157CVEs
CVE-2021-0211
Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
Published 2021-01-15 · Modified
10.0EPSS 0.013
CVE-2021-0254
Junos OS: Remote code execution vulnerability in overlayd service
Published 2021-04-22 · Modified
9.8EPSS 0.026
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2021-0266
cSRX: Use of Hard-coded Cryptographic Keys allows an attacker to take control of the device through device management services.
Published 2021-04-22 · Modified
9.8EPSS 0.009
CVE-2022-22167
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy
Published 2022-01-19 · Modified
9.8EPSS 0.007
CVE-2023-28962
Junos OS: Unauthenticated access vulnerability in J-Web
Published 2023-04-17 · Modified
9.8EPSS 0.006
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2021-0278
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-07-15 · Modified
8.8EPSS 0.009
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-0277
Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
Published 2021-07-15 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2021-31373
Junos OS: SRX Series: Persistent XSS vulnerability in J-Web
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2022-22181
Junos OS: J-Web can be compromised through reflected XSS attacks
Published 2022-04-14 · Modified
8.0EPSS 0.007
CVE-2021-31368
Junos OS: EX2300 Series, EX3400 Series, and ACX710 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2021-10-19 · Modified
7.8EPSS 0.011
CVE-2021-0283
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-07-15 · Modified
7.8EPSS 0.010
CVE-2021-0284
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-08-17 · Modified
7.8EPSS 0.010
CVE-2021-31359
Junos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
Published 2021-10-19 · Modified
7.8EPSS 0.002
CVE-2022-22162
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in
Published 2022-01-19 · Modified
7.8EPSS 0.002
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2021-0255
Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
Published 2021-04-22 · Modified
7.8EPSS 0.002
CVE-2021-31353
Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update
Published 2021-10-19 · Modified
7.5EPSS 0.012
CVE-2022-22197
Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening
Published 2022-04-14 · Modified
7.5EPSS 0.011
CVE-2021-31351
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31374
Junos OS and Junos OS Evolved: RPD crash while processing a specially crafted BGP UPDATE or KEEPALIVE message.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31378
Junos OS: An attacker sending spoofed RADIUS messages to a Junos OS device configured for broadband services may cause broadband subscribers to remain stuck in a "Terminating" state.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31383
Junos OS and Junos OS Evolved: In Point to MultiPoint (P2MP) scenarios receipt of various crafted packets causes RPD to core.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-0264
Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11, PTX10003, PTX10008: Line card may crash and restart when traffic is hitting a firewall filter having a term with syslog action configured
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2022-22185
Junos OS: SRX Series: Denial of service vulnerability in flowd daemon upon receipt of a specific fragmented packet
Published 2022-04-14 · Modified
7.5EPSS 0.010
CVE-2022-22161
Junos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2022-01-19 · Modified
7.5EPSS 0.010
CVE-2021-0280
Junos OS: PTX Series, QFX10K Series: Upon receipt of specific packets BFD sessions might flap due to DDoS policer implementation in Packet Forwarding Engine
Published 2021-07-15 · Modified
7.5EPSS 0.010
CVE-2021-0230
Junos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statistics
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2021-0285
Junos OS: QFX5000 Series and EX4600 Series: Continuous traffic destined to a device configured with MC-LAG leading to nodes losing their control connection which can impact traffic
Published 2021-07-15 · Modified
7.5EPSS 0.010
CVE-2022-22177
Junos OS and Junos OS Evolved: After receiving a specific number of crafted packets snmpd will segmentation fault (SIGSEGV) requiring a manual restart.
Published 2022-01-19 · Modified
7.5EPSS 0.010
CVE-2022-22171
Junos OS: Specific packets over VXLAN cause FPC reset
Published 2022-01-19 · Modified
7.5EPSS 0.009
1 / 4Next →