VendorsJunipersrx220all versions
Vulnerabilities

Juniper SRX220

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

94CVEs
CVE-2018-0009
SRX Series: Firewall bypass vulnerability when UUID with leading zeros is configured.
Published 2018-01-10 · Modified
5.9EPSS 0.013
CVE-2019-0015
Junos OS: SRX Series: Deleted dynamic VPN users are allowed to establish VPN connections until reboot
Published 2019-01-15 · Modified
5.5EPSS 0.008
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2023-22409
Junos OS: SRX Series, MX Series with SPC3: When an inconsistent NAT configuration exists and a specific CLI command is issued the SPC will reboot
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2014-3822
Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4.
Published 2014-07-11 · Modified
5.4EPSS 0.017
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2022-22204
Junos OS: MX Series and SRX Series: When receiving a specific SIP packets stale call table entries are created which eventually leads to a DoS for all SIP traffic
Published 2022-07-20 · Modified
5.3EPSS 0.007
CVE-2023-28968
Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open
Published 2023-04-17 · Modified
5.3EPSS 0.006
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562
CVE-2014-0612
Unspecified vulnerability in Juniper Junos before 11.4R10-S1, before 11.4R11, 12.1X44 before 12.1X44-D26, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, and 12.1X46 before 12.1X46-D10, when Dynamic IPsec VPN is configured, allows remote attackers to cause a denial of service (new Dynamic VPN connection failures and CPU and disk consumption) via unknown vectors.
Published 2014-04-14 · Modified
5.0EPSS 0.016
CVE-2015-5363
The SRX Network Security Daemon (nsd) in Juniper SRX Series services gateways with Junos 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 allows remote DNS servers to cause a denial of service (crash) via a crafted DNS response.
Published 2015-07-16 · Modified
5.0EPSS 0.013
CVE-2013-6015
Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.
Published 2013-10-17 · Modified
4.3EPSS 0.020
CVE-2015-3005
Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-04-10 · Modified
4.3EPSS 0.018
← Prev3 / 3