VendorsJunipervsrxall versions
Vulnerabilities

Juniper vSRX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2019-0062
Junos OS: Session fixation vulnerability in J-Web
Published 2019-10-09 · Modified
8.8EPSS 0.011
CVE-2017-2341
Junos OS: VM to host privilege escalation in platforms with Junos OS running in a virtualized environment.
Published 2017-07-14 · Modified
8.8EPSS 0.004
CVE-2024-39540
Junos OS: SRX Series, and MX Series with SPC3: Specific valid TCP traffic can cause a pfe crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Published 2016-03-09 · Modified
8.6EPSS 0.621
CVE-2025-59968
Junos Space Security Director: Insufficient authorization for sensitive resources in web interface
Published 2025-10-09 · Analyzed
8.6EPSS 0.003
CVE-2026-57022
Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2014-6451
J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service (system reboot) via unspecified vectors.
Published 2015-10-16 · Modified
7.8EPSS 0.019
CVE-2019-0058
Junos OS: SRX Series: A weakness in the Veriexec subsystem may allow privilege escalation.
Published 2019-10-09 · Modified
7.8EPSS 0.003
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0060
Junos OS: SRX Series: flowd process crash due to processing of specific transit IP packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2022-22201
SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet
Published 2022-10-18 · Modified
7.5EPSS 0.007
CVE-2023-36831
Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2023-28985
SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
Published 2023-07-14 · Modified
7.5EPSS 0.006
CVE-2019-0054
Junos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.
Published 2019-10-09 · Modified
7.4EPSS 0.006
CVE-2018-0053
vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting.
Published 2018-10-10 · Modified
7.2EPSS 0.005
CVE-2024-21609
Junos OS: MX Series with SPC3, and SRX Series: If specific IPsec parameters are negotiated iked will crash due to a memory leak
Published 2024-04-12 · Analyzed
7.1EPSS 0.003
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2021-0231
Junos OS: SRX, vSRX Series: J-Web Path traversal vulnerability in SRX and vSRX Series leads to information disclosure.
Published 2021-04-22 · Modified
6.8EPSS 0.012
CVE-2024-30391
Junos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performed
Published 2024-04-12 · Analyzed
6.3EPSS 0.004
CVE-2019-0069
Junos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear text
Published 2019-10-09 · Modified
5.9EPSS 0.002
CVE-2020-1682
Junos OS: SRX1500, vSRX, SRX4K, NFX150, NFX250: Denial of service vulnerability executing local CLI command
Published 2020-10-16 · Modified
5.5EPSS 0.003
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002