VendorsJunipersrx240many version
Vulnerabilities

Juniper SRX240m any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
Published 2023-08-17 · Analyzed
9.8KEVEPSS 0.951
CVE-2018-0045
Junos OS: RPD daemon crashes due to receipt of specific Draft-Rosen MVPN control packet in Draft-Rosen MVPN configuration
Published 2018-10-10 · Modified
8.8EPSS 0.011
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2024-39540
Junos OS: SRX Series, and MX Series with SPC3: Specific valid TCP traffic can cause a pfe crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2024-39529
Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Published 2016-03-09 · Modified
8.6EPSS 0.621
CVE-2017-3145
Improper fetch cleanup sequencing in the resolver can cause named to crash
Published 2019-01-16 · Modified
7.5EPSS 0.279
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2023-22415
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2022-22236
Junos OS: SRX Series and MX Series: When specific valid SIP packets are received the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2022-22232
SRX Series: If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific traffic is processed the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-22416
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is received
Published 2023-01-12 · Modified
7.5EPSS 0.007
CVE-2023-22417
Junos OS: SRX Series: A memory leak might be observed in IPsec VPN scenario leading to an FPC crash
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2022-22235
Junos OS: SRX Series: A flowd core will be observed when malformed GPRS traffic is processed
Published 2022-10-18 · Modified
7.5EPSS 0.006
CVE-2023-36831
Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28985
SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-22394
Junos OS: SRX Series and MX Series: Memory leak due to receipt of specially crafted SIP calls
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2023-22411
Junos OS: SRX Series: The flow processing daemon (flowd) will crash when Unified Policies are used with IPv6 and certain dynamic applications are rejected by the device
Published 2023-01-12 · Modified
7.5EPSS 0.006
CVE-2024-21606
Junos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crash
Published 2024-01-12 · Modified
7.5EPSS 0.006
CVE-2023-22412
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if the SIP ALG is enabled and specific SIP messages are processed
Published 2023-01-12 · Modified
7.5EPSS 0.005
CVE-2022-22218
Junos OS: SRX Series: Upon processing of a genuine packet the pkid process will crash during CMPv2 auto-re-enrollment
Published 2022-10-18 · Modified
7.5EPSS 0.004
CVE-2024-21609
Junos OS: MX Series with SPC3, and SRX Series: If specific IPsec parameters are negotiated iked will crash due to a memory leak
Published 2024-04-12 · Analyzed
7.1EPSS 0.003
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2023-22404
Junos OS: SRX Series and MX Series with SPC3: When IPsec VPN is configured iked will core when a specifically formatted payload is received
Published 2023-01-12 · Modified
6.5EPSS 0.006
CVE-2024-30391
Junos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performed
Published 2024-04-12 · Analyzed
6.3EPSS 0.004
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2023-22409
Junos OS: SRX Series, MX Series with SPC3: When an inconsistent NAT configuration exists and a specific CLI command is issued the SPC will reboot
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2023-28968
Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open
Published 2023-04-17 · Modified
5.3EPSS 0.006
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562