VendorsJunipermx40any version
Vulnerabilities

Juniper MX40 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

59CVEs
CVE-2019-0007
Junos OS: vMX series: Predictable IP ID sequence numbers vulnerability
Published 2019-01-15 · Modified
10.0EPSS 0.017
CVE-2021-0251
Junos OS: MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC: The BRAS Subscriber Services service activation portal is vulnerable to a Denial of Service (DoS) via malformed HTTP packets
Published 2021-04-22 · Modified
8.6EPSS 0.011
CVE-2018-0002
MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.
Published 2018-01-10 · Modified
8.2EPSS 0.015
CVE-2020-1608
Junos OS: MX Series: In BBE configurations, receipt of a specific MPLS or IPv6 packet causes a Denial of Service
Published 2020-01-15 · Modified
7.8EPSS 0.013
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2021-31379
Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
Published 2021-10-19 · Modified
7.5EPSS 0.013
CVE-2019-0063
Junos OS: MX Series: jdhcpd crash when receiving a specific crafted DHCP response message
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0065
Junos OS: MX Series: Denial of Service vulnerability in MS-PIC component on MS-MIC or MS-MPC
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2020-1649
Junos OS: MX Series: PFE crash on MPC7/8/9 upon receipt of small fragments requiring reassembly
Published 2020-07-17 · Modified
7.5EPSS 0.011
CVE-2020-1650
Junos OS: MX Series: Denial of Service vulnerability in MS-PIC component on MS-MIC or MS-MPC
Published 2020-07-17 · Modified
7.5EPSS 0.010
CVE-2021-0202
Junos OS: MX Series, EX9200 Series: Trio-based MPC memory leak when Integrated Routing and Bridging (IRB) interface is mapped to a VPLS instance or a Bridge-Domain
Published 2021-01-15 · Modified
7.5EPSS 0.010
CVE-2021-31351
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-0264
Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11, PTX10003, PTX10008: Line card may crash and restart when traffic is hitting a firewall filter having a term with syslog action configured
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2022-22178
Junos OS: MX and SRX series: Flowd core observed if the SIP ALG is enabled and a specific Session Initiation Protocol (SIP) packet is received
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22153
SRX Series and MX Series with SPC3: A high percentage of fragments might lead to high latency or packet drops
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22198
Junos OS: MX MS-MPC or MS-MIC, or SRX SPC crashes if it receives a SIP message with a specific contact header format
Published 2022-04-14 · Modified
7.5EPSS 0.009
CVE-2023-22415
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2023-22410
Junos OS: MX Series with MPC10/MPC11: When Suspicious Control Flow Detection (scfd) is enabled and an attacker is sending specific traffic, this causes a memory leak.
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2022-22207
Junos OS: MX Series with MPC11: In a GNF / node slicing scenario gathering AF interface statistics can lead to a kernel crash
Published 2022-07-20 · Modified
7.5EPSS 0.008
CVE-2022-22175
Junos OS: MX Series and SRX Series: The flowd daemon will crash if the SIP ALG is enabled and specific SIP messages are processed
Published 2022-01-19 · Modified
7.5EPSS 0.007
CVE-2022-22236
Junos OS: SRX Series and MX Series: When specific valid SIP packets are received the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-22416
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is received
Published 2023-01-12 · Modified
7.5EPSS 0.007
CVE-2023-22413
Junos OS: MX Series: The Multiservices PIC Management Daemon (mspmand) will crash when an IPsec6 tunnel processes specific IPv4 packets
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-36832
Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28985
SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28976
Junos OS: MX Series: If a specific traffic rate goes above the DDoS threshold it will lead to an FPC crash
Published 2023-04-17 · Modified
7.5EPSS 0.006
CVE-2023-22394
Junos OS: SRX Series and MX Series: Memory leak due to receipt of specially crafted SIP calls
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-22412
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if the SIP ALG is enabled and specific SIP messages are processed
Published 2023-01-12 · Modified
7.5EPSS 0.005
CVE-2020-1633
Junos OS: MX Series: Crafted packets traversing a Broadband Network Gateway (BNG) configured with IPv6 NDP proxy could lead to Denial of Service
Published 2020-04-09 · Modified
7.4EPSS 0.005
CVE-2023-28974
Junos OS: MX Series: In a BBE scenario upon receipt of specific malformed packets from subscribers the process bbe-smgd will crash
Published 2023-04-17 · Modified
7.4EPSS 0.003
CVE-2014-6382
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.
Published 2015-01-16 · Modified
7.1EPSS 0.012
CVE-2024-30378
Junos OS: MX Series: bbe-smgd process crash upon execution of specific CLI commands
Published 2024-04-16 · Analyzed
6.9EPSS 0.002
CVE-2017-10611
Junos: EX Series PFE and MX MPC7E/8E/9E PFE crash when fetching interface stats with 'extended-statistics' enabled
Published 2017-10-13 · Modified
6.5EPSS 0.009
CVE-2023-22404
Junos OS: SRX Series and MX Series with SPC3: When IPsec VPN is configured iked will core when a specifically formatted payload is received
Published 2023-01-12 · Modified
6.5EPSS 0.006
CVE-2022-22249
Junos OS: MX Series: An FPC crash might be seen due to mac-moves within the same bridge domain
Published 2022-10-18 · Modified
6.5EPSS 0.005
CVE-2020-1651
Junos OS: MX Series: PFE on the line card may crash due to memory leak.
Published 2020-07-17 · Modified
6.5EPSS 0.005
CVE-2021-31366
Junos OS: MX Series: In subscriber management / BBE configuration authd can crash if a subscriber with a specific username tries to login leading to a DoS
Published 2021-10-19 · Modified
6.5EPSS 0.004
CVE-2021-0228
Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0257
Junos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interface
Published 2021-04-22 · Modified
6.5EPSS 0.004
CVE-2021-0288
Junos OS: MX Series, EX9200 Series: FPC may crash upon receipt of specific MPLS packet affecting Trio-based MPCs
Published 2021-07-15 · Modified
6.5EPSS 0.004
1 / 2Next →