VendorsJunipersrx4100any version
Vulnerabilities

Juniper SRX4100 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

126CVEs
CVE-2025-52960
Junos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crash
Published 2025-10-09 · Analyzed
8.2EPSS 0.003
CVE-2024-47506
Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash
Published 2024-10-11 · Analyzed
8.2EPSS 0.003
CVE-2018-0025
Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication
Published 2018-07-11 · Modified
8.1EPSS 0.014
CVE-2020-1606
Junos OS: Path traversal vulnerability in J-Web
Published 2020-01-15 · Modified
8.1EPSS 0.009
CVE-2021-31373
Junos OS: SRX Series: Persistent XSS vulnerability in J-Web
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2018-0020
Junos OS: rpd daemon cores due to malformed BGP UPDATE packet
Published 2018-04-11 · Modified
7.8EPSS 0.013
CVE-2018-0024
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Published 2018-07-11 · Modified
7.8EPSS 0.004
CVE-2019-0058
Junos OS: SRX Series: A weakness in the Veriexec subsystem may allow privilege escalation.
Published 2019-10-09 · Modified
7.8EPSS 0.003
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2017-3145
Improper fetch cleanup sequencing in the resolver can cause named to crash
Published 2019-01-16 · Modified
7.5EPSS 0.279
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2018-0018
SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.
Published 2018-04-11 · Modified
7.5EPSS 0.016
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0060
Junos OS: SRX Series: flowd process crash due to processing of specific transit IP packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2021-0227
Junos OS: SRX Series: Denial of Service in J-Web upon receipt of crafted HTTP packets
Published 2021-04-22 · Modified
7.5EPSS 0.013
CVE-2021-0206
Junos OS: NFX Series, SRX Series: PFE may crash upon receipt of specific packet when SSL Proxy is configured.
Published 2021-01-15 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2020-1634
Junos OS: High-End SRX Series: Multicast traffic might cause all FPCs to reset.
Published 2020-04-08 · Modified
7.5EPSS 0.013
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
CVE-2020-1601
Junos OS: Upon receipt of certain types of malformed PCEP packets the pccd process may crash.
Published 2020-01-15 · Modified
7.5EPSS 0.011
CVE-2022-22185
Junos OS: SRX Series: Denial of service vulnerability in flowd daemon upon receipt of a specific fragmented packet
Published 2022-04-14 · Modified
7.5EPSS 0.010
CVE-2021-0230
Junos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statistics
Published 2021-04-22 · Modified
7.5EPSS 0.010
CVE-2022-22178
Junos OS: MX and SRX series: Flowd core observed if the SIP ALG is enabled and a specific Session Initiation Protocol (SIP) packet is received
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22153
SRX Series and MX Series with SPC3: A high percentage of fragments might lead to high latency or packet drops
Published 2022-01-19 · Modified
7.5EPSS 0.009
CVE-2022-22198
Junos OS: MX MS-MPC or MS-MIC, or SRX SPC crashes if it receives a SIP message with a specific contact header format
Published 2022-04-14 · Modified
7.5EPSS 0.009
CVE-2024-21619
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
Published 2024-01-25 · Modified
7.5EPSS 0.009
CVE-2020-1607
Junos OS: Cross-Site Scripting (XSS) in J-Web
Published 2020-01-15 · Modified
7.5EPSS 0.009
CVE-2022-22206
Junos OS: SRX series: The PFE will crash when specific traffic is scanned by Enhanced Web Filtering safe-search
Published 2022-07-20 · Modified
7.5EPSS 0.008
CVE-2022-22205
Junos OS: SRX Series: An FPC memory leak can occur in an APBR scenario
Published 2022-07-20 · Modified
7.5EPSS 0.008
CVE-2023-22415
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received
Published 2023-01-12 · Modified
7.5EPSS 0.008
CVE-2022-22175
Junos OS: MX Series and SRX Series: The flowd daemon will crash if the SIP ALG is enabled and specific SIP messages are processed
Published 2022-01-19 · Modified
7.5EPSS 0.007
CVE-2022-22231
SRX Series: If UTM Enhanced Content Filtering and AntiVirus are enabled, and specific traffic is processed the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2022-22232
SRX Series: If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific traffic is processed the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2022-22236
Junos OS: SRX Series and MX Series: When specific valid SIP packets are received the PFE will crash
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2022-22201
SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-22416
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is received
Published 2023-01-12 · Modified
7.5EPSS 0.007
← Prev2 / 4Next →