VYPR

Vendor CVEs

Juniper Networks

All CVEs

1,117 total · sorted by risk
  • CVE-2025-52986MedJul 11, 2025
    risk 0.36cvss 5.5epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a…

  • CVE-2025-52963MedJul 11, 2025
    risk 0.36cvss 5.5epss 0.00

    An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Users with "view" permissions can run a specific request…

  • CVE-2025-30655MedApr 9, 2025
    risk 0.36cvss 5.5epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific "show bgp neighbor" CLI…

  • CVE-2025-30654MedApr 9, 2025
    risk 0.36cvss 5.5epss 0.00

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information.  Through the…

  • CVE-2025-30652MedApr 9, 2025
    risk 0.36cvss 5.5epss 0.00

    An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). When asregex-optimized is…

  • CVE-2025-21596MedJan 9, 2025
    risk 0.36cvss 5.5epss 0.00

    An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' command to cause…

  • CVE-2025-21592MedJan 9, 2025
    risk 0.36cvss 5.5epss 0.00

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the…

  • CVE-2024-47501MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In a…

  • CVE-2024-47496MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific command is executed, the pfe crashes. This will cause traffic forwarding to…

  • CVE-2024-39527MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the…

  • CVE-2024-39513MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a Denial of Service (DoS). When a specific "clear" command is run, the Advanced Forwarding Toolkit manager…

  • CVE-2024-39511MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x…

  • CVE-2024-30378MedApr 16, 2024
    risk 0.36cvss 5.5epss 0.00

    A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service…

  • CVE-2024-30384MedApr 12, 2024
    risk 0.36cvss 5.5epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows a locally authenticated attacker with low privileges to cause a Denial-of-Service (Dos). If a specific CLI command…

  • CVE-2024-30406MedApr 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on network devices allows a local, authenticated attacker with high privileges to read all other users…

  • CVE-2024-21594MedJan 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). On an SRX 5000 Series device, when executing a specific command repeatedly,…

  • CVE-2023-44193MedOct 13, 2023
    risk 0.36cvss 5.5epss 0.00

    An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). On all Junos MX Series with MPC1 - MPC9,…

  • CVE-2023-44178MedOct 13, 2023
    risk 0.36cvss 5.5epss 0.00

    A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS)…

  • CVE-2023-44177MedOct 13, 2023
    risk 0.36cvss 5.5epss 0.00

    A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service…

  • CVE-2023-44176MedOct 13, 2023
    risk 0.36cvss 5.5epss 0.00

    A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS)…

  • CVE-2023-36840MedJul 14, 2023
    risk 0.36cvss 5.5epss 0.00

    A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved, when a specific L2VPN command is run,…

  • CVE-2023-36838MedJul 14, 2023
    risk 0.36cvss 5.5epss 0.00

    An Out-of-bounds Read vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a local, authenticated attacker with low privileges, to cause a Denial of Service (DoS). If a low privileged user executes a specific CLI command, flowd…

  • CVE-2023-28980MedApr 17, 2023
    risk 0.36cvss 5.5epss 0.00

    A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause Denial of Service (DoS). In a rib sharding scenario the rpd process will crash shortly after…

  • CVE-2023-22409MedJan 13, 2023
    risk 0.36cvss 5.5epss 0.00

    An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS). When an inconsistent "deterministic NAT" configuration is present on an SRX, or MX with…

  • CVE-2022-22240MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…

  • CVE-2022-22234MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). If the…

  • CVE-2022-22233MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In Segment Routing (SR) to Label…

  • CVE-2022-22193MedApr 14, 2022
    risk 0.36cvss 5.5epss 0.00

    An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Continued execution of this command…

  • CVE-2021-31377MedOct 19, 2021
    risk 0.36cvss 5.5epss 0.00

    An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated actions by the…

  • CVE-2021-0293MedJul 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI command 'show system connections extensive' is executed. The amount of memory leaked on each execution depends on the number of TCP…

  • CVE-2021-0256MedApr 22, 2021
    risk 0.36cvss 5.5epss 0.00

    A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability to read portions of sensitive files, such as the master.passwd file. Since mosquitto is shipped with…

  • CVE-2021-0255MedApr 22, 2021
    risk 0.36cvss 5.5epss 0.00

    A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticated user with shell access to escalate privileges and write to the local filesystem as root. ethtraceroute is shipped with setuid permissions enabled and is…

  • CVE-2021-0238MedApr 22, 2021
    risk 0.36cvss 5.5epss 0.00

    When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cause the system to run out of disk space, excessive disk usage may cause other complications. An administrator can use the following…

  • CVE-2020-1682MedOct 16, 2020
    risk 0.36cvss 5.5epss 0.00

    An input validation vulnerability exists in Juniper Networks Junos OS, allowing an attacker to crash the srxpfe process, causing a Denial of Service (DoS) through the use of specific maintenance commands. The srxpfe process restarts automatically, but continuous execution of the…

  • CVE-2020-1652MedJul 17, 2020
    risk 0.36cvss 5.6epss 0.01

    OpenNMS is accessible via port 9443

  • CVE-2020-1643MedJul 17, 2020
    risk 0.36cvss 5.5epss 0.00

    Execution of the "show ospf interface extensive" or "show ospf interface detail" CLI commands on a Juniper Networks device running Junos OS may cause the routing protocols process (RPD) to crash and restart if OSPF interface authentication is configured, leading to a Denial of…

  • CVE-2020-7656MedMay 19, 2020
    risk 0.36cvss 6.1epss 0.06

    jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "", which results in the enclosed script logic to be executed.

  • CVE-2020-1624MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1.

  • CVE-2020-1623MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1.

  • CVE-2020-1622MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.

  • CVE-2020-1621MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

  • CVE-2020-1620MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

  • CVE-2019-0074MedOct 9, 2019
    risk 0.36cvss 5.5epss 0.00

    A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system files. This issue only affects NFX150 Series and QFX10K…

  • CVE-2019-0072MedOct 9, 2019
    risk 0.36cvss 5.6epss 0.00

    An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R13;…

  • CVE-2019-0009MedJan 15, 2019
    risk 0.36cvss 5.5epss 0.00

    On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine (PFE). In a virtual chassis (VC) deployment, this issue disrupts communication between the VC members. This issue does not affect…

  • CVE-2019-0004MedJan 15, 2019
    risk 0.36cvss 5.5epss 0.00

    On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

  • CVE-2018-0023MedApr 11, 2018
    risk 0.36cvss 5.5epss 0.00

    JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and sample files of JSNAPy automation tool versions prior to 1.3.0 are created world writable. This insecure file and directory…

  • CVE-2017-10613MedOct 13, 2017
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a running configuration of Juniper Networks Junos OS, allows an attacker with CLI access and the ability to initiate remote sessions to the loopback interface…

  • CVE-2017-2322MedApr 24, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which are normally reserved for…

  • CVE-2017-2328MedApr 24, 2017
    risk 0.36cvss 5.5epss 0.00

    An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller.

Page 17 of 23