VendorsJunipersrx2300any version
Vulnerabilities

Juniper SRX2300 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2024-39565
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
Published 2024-07-10 · Analyzed
8.8EPSS 0.005
CVE-2024-47497
Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2026-21906
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.006
CVE-2024-39545
Junos OS: SRX Series, MX Series with SPC3 and NFX350: When VPN tunnels parameters are not configured in specific way the iked process will crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2024-39540
Junos OS: SRX Series, and MX Series with SPC3: Specific valid TCP traffic can cause a pfe crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2026-21920
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.005
CVE-2024-39551
Junos OS: SRX Series and MX Series with SPC3 and MS-MPC/MIC: Receipt of specific packets in H.323 ALG causes traffic drop
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2024-39529
Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2026-57026
Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2026-57023
Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2025-52981
Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash
Published 2025-07-11 · Analyzed
8.7EPSS 0.004
CVE-2025-30658
Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30659
Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30645
Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2025-30656
Junos OS: MX Series, SRX Series: Processing of specific SIP INVITE messages by the SIP ALG will lead to an FPC crash
Published 2025-04-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21905
Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-21917
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-21918
Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-33778
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
Published 2026-04-09 · Analyzed
8.7EPSS 0.003
CVE-2026-33790
Junos OS: SRX Series: In a NAT64 configuration, receipt of a specific, malformed ICMPv6 packet will cause the srxpfe process to crash and restart.
Published 2026-04-09 · Analyzed
8.7EPSS 0.003
CVE-2026-21914
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.003
CVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Published 2016-03-09 · Modified
8.6EPSS 0.621
CVE-2025-59968
Junos Space Security Director: Insufficient authorization for sensitive resources in web interface
Published 2025-10-09 · Analyzed
8.6EPSS 0.003
CVE-2026-33779
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
Published 2026-04-09 · Analyzed
8.3EPSS 0.001
CVE-2026-57022
Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2026-57030
Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2025-52960
Junos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crash
Published 2025-10-09 · Analyzed
8.2EPSS 0.003
CVE-2024-47506
Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash
Published 2024-10-11 · Analyzed
8.2EPSS 0.003
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2024-21606
Junos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crash
Published 2024-01-12 · Modified
7.5EPSS 0.006
CVE-2024-21586
Junos OS: SRX Series and NFX Series: Specific valid traffic leads to a PFE crash
Published 2024-07-01 · Analyzed
7.5EPSS 0.005
CVE-2023-44198
Junos OS: SRX Series and MX Series: SIP ALG doesn't drop specifically malformed retransmitted SIP packets
Published 2023-10-12 · Modified
7.5EPSS 0.004
CVE-2024-21609
Junos OS: MX Series with SPC3, and SRX Series: If specific IPsec parameters are negotiated iked will crash due to a memory leak
Published 2024-04-12 · Analyzed
7.1EPSS 0.003
CVE-2026-57021
Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash
Published 2026-07-09 · Analyzed
6.9EPSS 0.005
CVE-2026-57024
Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2025-6549
Junos OS: SRX Series: J-Web can be exposed on additional interfaces
Published 2025-07-11 · Analyzed
6.9EPSS 0.002
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2024-39527
Junos OS: SRX Series: Low privileged user able to access sensitive information on file system
Published 2024-10-11 · Analyzed
6.8EPSS 0.002
CVE-2025-21592
Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system
Published 2025-01-09 · Analyzed
6.8EPSS 0.002
1 / 2Next →