VendorsJuniperjunos21.1
Vulnerabilities

Juniper Junos 21.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

161CVEs
CVE-2021-31384
Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
Published 2021-10-19 · Modified
10.0EPSS 0.012
CVE-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
Published 2023-08-17 · Analyzed
9.8KEVEPSS 0.951
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2022-22167
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy
Published 2022-01-19 · Modified
9.8EPSS 0.007
CVE-2023-28962
Junos OS: Unauthenticated access vulnerability in J-Web
Published 2023-04-17 · Modified
9.8EPSS 0.006
CVE-2022-22157
Junos OS: SRX Series: Traffic classification vulnerability when 'no-syn-check' is enabled
Published 2022-01-19 · Modified
9.3EPSS 0.007
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2021-31385
Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root
Published 2021-10-19 · Modified
8.8EPSS 0.015
CVE-2021-0278
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-07-15 · Modified
8.8EPSS 0.009
CVE-2022-22182
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session
Published 2022-04-14 · Modified
8.8EPSS 0.007
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2023-44182
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
Published 2023-10-12 · Modified
8.8EPSS 0.006
CVE-2024-39530
Junos OS: Attempting to access specific sensors on platforms not supporting these will lead to a chassisd crash
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2023-44194
Junos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privileges
Published 2023-10-12 · Modified
8.4EPSS 0.002
CVE-2021-31355
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2022-22181
Junos OS: J-Web can be compromised through reflected XSS attacks
Published 2022-04-14 · Modified
8.0EPSS 0.007
CVE-2021-0283
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-07-15 · Modified
7.8EPSS 0.010
CVE-2021-0284
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore)
Published 2021-08-17 · Modified
7.8EPSS 0.010
CVE-2021-31359
Junos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
Published 2021-10-19 · Modified
7.8EPSS 0.002
CVE-2022-22162
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in
Published 2022-01-19 · Modified
7.8EPSS 0.002
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2023-4481
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Published 2023-08-31 · Modified
7.5EPSS 0.182
CVE-2021-31353
Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update
Published 2021-10-19 · Modified
7.5EPSS 0.012
CVE-2021-31351
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-31378
Junos OS: An attacker sending spoofed RADIUS messages to a Junos OS device configured for broadband services may cause broadband subscribers to remain stuck in a "Terminating" state.
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2022-22161
Junos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of traffic
Published 2022-01-19 · Modified
7.5EPSS 0.010
CVE-2022-22185
Junos OS: SRX Series: Denial of service vulnerability in flowd daemon upon receipt of a specific fragmented packet
Published 2022-04-14 · Modified
7.5EPSS 0.010
CVE-2022-22177
Junos OS and Junos OS Evolved: After receiving a specific number of crafted packets snmpd will segmentation fault (SIGSEGV) requiring a manual restart.
Published 2022-01-19 · Modified
7.5EPSS 0.010
CVE-2022-22178
Junos OS: MX and SRX series: Flowd core observed if the SIP ALG is enabled and a specific Session Initiation Protocol (SIP) packet is received
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22170
Junos OS: Specific packets over VXLAN cause FPC memory leak and ultimately reset
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22171
Junos OS: Specific packets over VXLAN cause FPC reset
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22180
Junos OS: EX2300 Series, EX2300-MP Series, EX3400 Series: A slow memory leak due to processing of specific IPv6 packets
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22174
Junos OS: QFX5000 Series, EX4600: Device may run out of memory, causing traffic loss, upon receipt of specific IPv6 packets
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22198
Junos OS: MX MS-MPC or MS-MIC, or SRX SPC crashes if it receives a SIP message with a specific contact header format
Published 2022-04-14 · Modified
7.5EPSS 0.009
CVE-2022-22223
Junos OS: QFX10000 Series: In IP/MPLS PHP node scenarios upon receipt of certain crafted packets multiple interfaces in LAG configurations may detach.
Published 2022-10-18 · Modified
7.5EPSS 0.008
CVE-2022-22206
Junos OS: SRX series: The PFE will crash when specific traffic is scanned by Enhanced Web Filtering safe-search
Published 2022-07-20 · Modified
7.5EPSS 0.008
CVE-2022-22205
Junos OS: SRX Series: An FPC memory leak can occur in an APBR scenario
Published 2022-07-20 · Modified
7.5EPSS 0.008
CVE-2023-22415
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2022-22207
Junos OS: MX Series with MPC11: In a GNF / node slicing scenario gathering AF interface statistics can lead to a kernel crash
Published 2022-07-20 · Modified
7.5EPSS 0.008
1 / 5Next →