VendorsJuniperjunos_os_evolved20.4
Vulnerabilities

Juniper JUNOS OS Evolved 20.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2021-31350
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
Published 2021-10-19 · Modified
9.0EPSS 0.009
CVE-2021-31354
Junos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)
Published 2021-10-19 · Modified
8.8EPSS 0.006
CVE-2022-22239
Junos OS Evolved: The ssh CLI command always runs as root which can lead to privilege escalation
Published 2022-10-18 · Modified
8.8EPSS 0.002
CVE-2024-21598
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
Published 2024-04-12 · Analyzed
8.7EPSS 0.006
CVE-2024-39524
Junos OS Evolved: CLI parameter processing issue allows privilege escalation
Published 2024-07-11 · Modified
8.5EPSS 0.003
CVE-2024-39523
Junos OS Evolved: CLI parameter processing issue allows privilege escalation
Published 2024-07-11 · Modified
8.5EPSS 0.003
CVE-2024-39520
Junos OS Evolved: CLI parameter processing issue allows privilege escalation
Published 2024-07-11 · Modified
8.5EPSS 0.003
CVE-2023-28960
Junos OS Evolved: Docker repository is world-writeable, allowing low-privileged local user to inject files into Docker containers
Published 2023-04-17 · Modified
8.2EPSS 0.002
CVE-2022-22195
Junos OS Evolved: Specific packets reaching the RE lead to a counter overflow and eventually a crash
Published 2022-04-14 · Modified
7.8EPSS 0.011
CVE-2021-0286
Junos OS Evolved: Specially crafted packets may cause the AFT manager process to crash and restart
Published 2021-07-15 · Modified
7.8EPSS 0.011
CVE-2022-22183
Junos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port.
Published 2022-04-14 · Modified
7.8EPSS 0.010
CVE-2021-31356
Junos OS Evolved: Multiple shell-injection vulnerabilities in EVO UI wrapper scripts
Published 2021-10-19 · Modified
7.8EPSS 0.009
CVE-2021-31357
Junos OS Evolved: shell-injection vulnerabilities in evo_tcpdump UI wrapper script
Published 2021-10-19 · Modified
7.8EPSS 0.006
CVE-2021-31358
Junos OS Evolved: shell-injection vulnerabilities in evo_sftp UI wrapper script
Published 2021-10-19 · Modified
7.8EPSS 0.006
CVE-2021-31359
Junos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
Published 2021-10-19 · Modified
7.8EPSS 0.002
CVE-2023-28966
Junos OS Evolved: Local low-privileged user with shell access can execute CLI commands as root
Published 2023-04-17 · Modified
7.8EPSS 0.002
CVE-2023-4481
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Published 2023-08-31 · Modified
7.5EPSS 0.182
CVE-2021-31353
Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update
Published 2021-10-19 · Modified
7.5EPSS 0.012
CVE-2022-22194
Junos OS Evolved: PTX series: An attacker sending a crafted GRE packet will cause the PFE to restart
Published 2022-04-14 · Modified
7.5EPSS 0.010
CVE-2021-0264
Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11, PTX10003, PTX10008: Line card may crash and restart when traffic is hitting a firewall filter having a term with syslog action configured
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2022-22192
Junos OS Evolved: PTX Series: An attacker can cause a kernel panic by sending a malformed TCP packet to the device
Published 2022-10-18 · Modified
7.5EPSS 0.008
CVE-2022-22211
Junos OS Evolved: PTX Series: Multiple FPCs become unreachable due to continuous polling of specific SNMP OID
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-28982
Junos OS and Junos OS Evolved: In a BGP rib sharding scenario when a route is frequently updated an rpd memory leak will occur
Published 2023-04-17 · Modified
7.5EPSS 0.006
CVE-2023-0026
2023-06: Out-of-Cycle Security Bulletin: Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute
Published 2023-06-21 · Modified
7.5EPSS 0.006
CVE-2023-22400
Junos OS Evolved: A specific SNMP GET operation and a specific CLI commands cause resources to leak and eventually the evo-pfemand process will crash
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-44186
Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor
Published 2023-10-11 · Modified
7.5EPSS 0.005
CVE-2023-44197
Junos OS and Junos OS Evolved: An rpd crash may occur when BGP is processing newly learned routes
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2023-44185
Junos OS and Junos OS Evolved: In an BGP scenario RPD crashes upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet
Published 2023-10-12 · Modified
7.5EPSS 0.005
CVE-2022-22248
Junos OS Evolved: Incorrect file permissions can allow low-privileged user to cause another user to execute arbitrary commands
Published 2022-10-18 · Modified
7.3EPSS 0.002
CVE-2024-39546
Junos OS Evolved: Local low-privilege user can gain root permissions leading to privilege escalation
Published 2024-07-11 · Analyzed
7.3EPSS 0.002
CVE-2024-30386
Junos OS and Junos OS Evolved: In a EVPN-VXLAN scenario state changes on adjacent systems can cause an l2ald process crash
Published 2024-04-12 · Analyzed
7.1EPSS 0.003
CVE-2024-39558
Junos OS and Junos OS Evolved: Receipt of specific PIM packet causes rpd crash when PIM is configured along with MoFRR
Published 2024-07-10 · Analyzed
7.1EPSS 0.003
CVE-2024-39514
Junos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crash
Published 2024-07-10 · Analyzed
7.1EPSS 0.002
CVE-2021-31360
Junos OS and Junos OS Evolved: Denial of Service vulnerability in local file processing
Published 2021-10-19 · Modified
7.1EPSS 0.002
CVE-2023-28973
Junos OS Evolved: The 'sysmanctl' shell command allows a local user to gain access to some administrative actions
Published 2023-04-17 · Modified
7.1EPSS 0.001
CVE-2024-39513
Junos OS Evolved: Execution of a specific CLI command will cause a crash in the AFT manager
Published 2024-07-10 · Analyzed
6.8EPSS 0.001
CVE-2021-0297
Junos OS Evolved: BGP and LDP sessions with TCP MD5 authentication established with peers not configured for authentication
Published 2021-10-19 · Modified
6.5EPSS 0.007
CVE-2022-22164
Junos OS Evolved: Telnet service may be enabled when it is expected to be disabled.
Published 2022-01-19 · Modified
6.5EPSS 0.007
CVE-2022-22215
Junos OS and Junos OS Evolved: /var/run/<pid>.env files are potentially not deleted during termination of a gRPC connection causing inode exhaustion
Published 2022-07-20 · Modified
6.5EPSS 0.006
CVE-2021-31362
Junos OS and Junos OS Evolved: An IS-IS adjacency might be taken down if a bad hello PDU is received for an existing adjacency causing a DoS
Published 2021-10-19 · Modified
6.5EPSS 0.004
1 / 2Next →