VYPR

Junos

by Juniper Networks

CVEs (796)

  • CVE-2020-1670MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300 Series, receipt of a stream of specific IPv4 packets can cause Routing Engine (RE) high CPU load, which could lead to network protocol operation issue and traffic interruption. This specific packets can originate only from within the broadcast domain…

  • CVE-2020-1668MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX2300 Series, receipt of a stream of specific multicast packets by the layer2 interface can cause high CPU load, which could lead to traffic interruption. This issue occurs when multicast packets are received by the layer 2 interface. To check if the device…

  • CVE-2020-1651MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.00

    On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE) on the line card to crash and restart, causing traffic interruption. By continuously sending this stream of specific layer 2…

  • CVE-2020-1641MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.00

    A Race Condition vulnerability in Juniper Networks Junos OS LLDP implementation allows an attacker to cause LLDP to crash leading to a Denial of Service (DoS). This issue occurs when crafted LLDP packets are received by the device from an adjacent device. Multiple LACP flaps…

  • CVE-2020-1625MedApr 8, 2020
    risk 0.42cvss 6.5epss 0.01

    The kernel memory usage represented as "temp" via 'show system virtual-memory' may constantly increase when Integrated Routing and Bridging (IRB) is configured with multiple underlay physical interfaces, and one interface flaps. This memory leak can affect running daemons…

  • CVE-2015-5361MedFeb 28, 2020
    risk 0.42cvss 6.5epss 0.00

    Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and ports of client and server. The design…

  • CVE-2015-3006MedFeb 28, 2020
    risk 0.42cvss 6.5epss 0.01

    On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been…

  • CVE-2020-1604MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets destined to the device Routing Engine…

  • CVE-2020-1600MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite loop causing a high CPU usage Denial of…

  • CVE-2019-0068MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packets. By continuously sending the specific multicast packets, an attacker can repeatedly crash the flowd process causing a sustained Denial of Service. This…

  • CVE-2019-0067MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Receipt of a specific link-local IPv6 packet destined to the RE may cause the system to crash and restart (vmcore). By continuously sending a specially crafted IPv6 packet, an attacker can repeatedly crash the system causing a prolonged Denial of Service (DoS). This issue…

  • CVE-2019-0063MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 enabled, jdhcpd might crash when receiving a specific crafted DHCP response message on a subscriber interface. The daemon automatically restarts without…

  • CVE-2019-0051MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    SSL-Proxy feature on SRX devices fails to handle a hardware resource limitation which can be exploited by remote SSL/TLS servers to crash the flowd daemon. Repeated crashes of the flowd daemon can result in an extended denial of service condition. For this issue to occur,…

  • CVE-2019-0046MedJul 11, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the EX4300 when specific valid broadcast packets create a broadcast storm condition when received on the me0 interface of the…

  • CVE-2019-0038MedApr 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are…

  • CVE-2019-0013MedJan 15, 2019
    risk 0.42cvss 6.5epss 0.02

    The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is received. While RPD restarts after a crash, repeated crashes can result in an extended Denial of Service (DoS) condition. This issue only affects IPv4 PIM. IPv6 PIM…

  • CVE-2019-0011MedJan 15, 2019
    risk 0.42cvss 6.5epss 0.01

    The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By continuously sending this type of packet, an attacker can repeatedly crash the kernel causing a…

  • CVE-2018-0063MedOct 10, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing interfaces (IRIs) next-hop limit. Once the IRI next-hop database is full, no further next hops can be…

  • CVE-2018-0056MedOct 10, 2018
    risk 0.42cvss 6.5epss 0.01

    If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to delete the duplicate MAC…

  • CVE-2018-0055MedOct 10, 2018
    risk 0.42cvss 6.5epss 0.01

    Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband Edge (BBE) environment may result in a jdhcpd daemon crash. The daemon automatically restarts without intervention, but a continuous receipt of crafted DHCPv6…

Page 26 of 40