VendorsJunipersrx4000any version
Vulnerabilities

Juniper SRX4000 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2023-22404
Junos OS: SRX Series and MX Series with SPC3: When IPsec VPN is configured iked will core when a specifically formatted payload is received
Published 2023-01-12 · Modified
6.5EPSS 0.006
CVE-2015-5361
Junos: FTPS through SRX opens up wide range of data channel TCP ports
Published 2020-02-28 · Modified
6.5EPSS 0.005
CVE-2021-0289
Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted
Published 2021-07-15 · Modified
6.5EPSS 0.003
CVE-2024-30391
Junos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performed
Published 2024-04-12 · Analyzed
6.3EPSS 0.004
CVE-2019-0069
Junos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear text
Published 2019-10-09 · Modified
5.9EPSS 0.002
CVE-2019-0015
Junos OS: SRX Series: Deleted dynamic VPN users are allowed to establish VPN connections until reboot
Published 2019-01-15 · Modified
5.5EPSS 0.008
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2023-22409
Junos OS: SRX Series, MX Series with SPC3: When an inconsistent NAT configuration exists and a specific CLI command is issued the SPC will reboot
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2022-22204
Junos OS: MX Series and SRX Series: When receiving a specific SIP packets stale call table entries are created which eventually leads to a DoS for all SIP traffic
Published 2022-07-20 · Modified
5.3EPSS 0.007
CVE-2023-28968
Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open
Published 2023-04-17 · Modified
5.3EPSS 0.006
CVE-2014-9708
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Published 2015-03-31 · Modified
5.0EPSS 0.562
← Prev2 / 2