VendorsJunipersrx5600all versions
Vulnerabilities

Juniper SRX5600

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

153CVEs
CVE-2018-0002
MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.
Published 2018-01-10 · Modified
8.2EPSS 0.015
CVE-2026-57022
Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2026-57030
Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2025-52960
Junos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crash
Published 2025-10-09 · Analyzed
8.2EPSS 0.003
CVE-2024-47506
Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash
Published 2024-10-11 · Analyzed
8.2EPSS 0.003
CVE-2018-0025
Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication
Published 2018-07-11 · Modified
8.1EPSS 0.014
CVE-2020-1606
Junos OS: Path traversal vulnerability in J-Web
Published 2020-01-15 · Modified
8.1EPSS 0.009
CVE-2021-31373
Junos OS: SRX Series: Persistent XSS vulnerability in J-Web
Published 2021-10-19 · Modified
8.0EPSS 0.008
CVE-2014-0618
Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP message.
Published 2014-01-11 · Modified
7.8EPSS 0.036
CVE-2014-3817
Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.
Published 2014-07-11 · Modified
7.8EPSS 0.034
CVE-2013-4684
flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R8, 12.1 before 12.1R7, and 12.1X44 before 12.1X44-D15 on SRX devices, when PIM and NAT are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted PIM packets, aka PR 842253.
Published 2013-07-11 · Modified
7.8EPSS 0.028
CVE-2013-4687
flowd in Juniper Junos 10.4 before 10.4S14, 11.2 and 11.4 before 11.4R6-S2, and 12.1 before 12.1R6 on SRX devices, when certain Application Layer Gateways (ALGs) are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted TCP packets, aka PRs 727980, 806269, and 835593.
Published 2013-07-11 · Modified
7.8EPSS 0.026
CVE-2013-4688
flowd in Juniper Junos 10.4 before 10.4R11 on SRX devices, when the MSRPC Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted MSRPC requests, aka PR 772834.
Published 2013-07-11 · Modified
7.8EPSS 0.019
CVE-2019-0052
SRX Series: srxpfe process crash while JSF/UTM module parses specific HTTP packets
Published 2019-07-11 · Modified
7.8EPSS 0.018
CVE-2014-3815
Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
Published 2014-07-11 · Modified
7.8EPSS 0.018
CVE-2018-0020
Junos OS: rpd daemon cores due to malformed BGP UPDATE packet
Published 2018-04-11 · Modified
7.8EPSS 0.013
CVE-2018-0024
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Published 2018-07-11 · Modified
7.8EPSS 0.004
CVE-2019-0058
Junos OS: SRX Series: A weakness in the Veriexec subsystem may allow privilege escalation.
Published 2019-10-09 · Modified
7.8EPSS 0.003
CVE-2022-22221
Junos OS: SRX and EX Series: Local privilege escalation flaw in "download" functionality
Published 2022-07-20 · Modified
7.8EPSS 0.002
CVE-2017-3145
Improper fetch cleanup sequencing in the resolver can cause named to crash
Published 2019-01-16 · Modified
7.5EPSS 0.279
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2019-0010
Junos OS: SRX Series: Crafted HTTP traffic may cause UTM to consume all mbufs, leading to Denial of Service
Published 2019-01-15 · Modified
7.5EPSS 0.027
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2019-0033
SRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2018-0018
SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.
Published 2018-04-11 · Modified
7.5EPSS 0.016
CVE-2019-0044
Junos OS: SRX5000 series: Kernel crash (vmcore) upon receipt of a specific packet on fxp0 interface
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0060
Junos OS: SRX Series: flowd process crash due to processing of specific transit IP packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2021-0227
Junos OS: SRX Series: Denial of Service in J-Web upon receipt of crafted HTTP packets
Published 2021-04-22 · Modified
7.5EPSS 0.013
CVE-2021-0206
Junos OS: NFX Series, SRX Series: PFE may crash upon receipt of specific packet when SSL Proxy is configured.
Published 2021-01-15 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2017-10619
Junos: SRX cluster denial of service vulnerability in flowd due to multicast packets
Published 2017-10-13 · Modified
7.5EPSS 0.013
CVE-2020-1634
Junos OS: High-End SRX Series: Multicast traffic might cause all FPCs to reset.
Published 2020-04-08 · Modified
7.5EPSS 0.013
CVE-2019-0064
Junos OS: SRX5000 Series: flowd process crash due to receipt of specific TCP packet
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
CVE-2020-1601
Junos OS: Upon receipt of certain types of malformed PCEP packets the pccd process may crash.
Published 2020-01-15 · Modified
7.5EPSS 0.011
← Prev2 / 4Next →