VendorsJuniperjunos20.4
Vulnerabilities

Juniper Junos 20.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

208CVEs
CVE-2021-31384
Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
Published 2021-10-19 · Modified
10.0EPSS 0.012
CVE-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
Published 2023-08-17 · Analyzed
9.8KEVEPSS 0.951
CVE-2024-21591
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution
Published 2024-01-12 · Analyzed
9.8EPSS 0.175
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2021-0266
cSRX: Use of Hard-coded Cryptographic Keys allows an attacker to take control of the device through device management services.
Published 2021-04-22 · Modified
9.8EPSS 0.009
CVE-2022-22167
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy
Published 2022-01-19 · Modified
9.8EPSS 0.007
CVE-2023-28962
Junos OS: Unauthenticated access vulnerability in J-Web
Published 2023-04-17 · Modified
9.8EPSS 0.006
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31382
Junos OS: PTX1000 System, PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces
Published 2021-10-19 · Modified
9.0EPSS 0.006
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2021-0278
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-07-15 · Modified
8.8EPSS 0.009
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-0277
Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
Published 2021-07-15 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2023-44182
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
Published 2023-10-12 · Modified
8.8EPSS 0.006
CVE-2024-30382
Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-39552
Junos OS and Junos OS Evolved: Malformed BGP UPDATE causes RPD crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.006
CVE-2024-21598
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
Published 2024-04-12 · Analyzed
8.7EPSS 0.006
CVE-2024-39551
Junos OS: SRX Series and MX Series with SPC3 and MS-MPC/MIC: Receipt of specific packets in H.323 ALG causes traffic drop
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2024-30397
Junos OS: An invalid certificate causes a Denial of Service in the Internet Key Exchange (IKE) process
Published 2024-04-12 · Modified
8.7EPSS 0.003
CVE-2023-44194
Junos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privileges
Published 2023-10-12 · Modified
8.4EPSS 0.002
CVE-2024-30402
Junos OS and Junos OS Evolved: The l2ald crashes on receiving telemetry messages from a specific subscription
Published 2024-04-12 · Analyzed
8.2EPSS 0.005
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2022-22181
Junos OS: J-Web can be compromised through reflected XSS attacks
Published 2022-04-14 · Modified
8.0EPSS 0.007
CVE-2021-31368
Junos OS: EX2300 Series, EX3400 Series, and ACX710 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2021-10-19 · Modified
7.8EPSS 0.011
CVE-2021-0283
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-07-15 · Modified
7.8EPSS 0.010
CVE-2021-0284
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-08-17 · Modified
7.8EPSS 0.010
CVE-2021-31359
Junos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
Published 2021-10-19 · Modified
7.8EPSS 0.002
CVE-2022-22162
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in
Published 2022-01-19 · Modified
7.8EPSS 0.002
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2021-0255
Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
Published 2021-04-22 · Modified
7.8EPSS 0.002
CVE-2023-4481
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Published 2023-08-31 · Modified
7.5EPSS 0.182
CVE-2021-31353
Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update
Published 2021-10-19 · Modified
7.5EPSS 0.012
CVE-2021-31351
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31378
Junos OS: An attacker sending spoofed RADIUS messages to a Junos OS device configured for broadband services may cause broadband subscribers to remain stuck in a "Terminating" state.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-0264
Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11, PTX10003, PTX10008: Line card may crash and restart when traffic is hitting a firewall filter having a term with syslog action configured
Published 2021-04-22 · Modified
7.5EPSS 0.010
1 / 6Next →