VYPR

Vendor CVEs

Juniper Networks

All CVEs

1,117 total · sorted by risk
  • CVE-2017-2327MedApr 24, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading to a cascading denial of services.

  • CVE-2025-60010MedOct 9, 2025
    risk 0.35cvss 5.4epss 0.00

    A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users for whom the RADIUS…

  • CVE-2025-60006MedOct 9, 2025
    risk 0.35cvss 5.3epss 0.01

    Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When an attacker…

  • CVE-2024-39534MedOct 11, 2024
    risk 0.35cvss 5.4epss 0.01

    An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the subnet assigned…

  • CVE-2024-21619MedJan 25, 2024
    risk 0.35cvss 5.3epss 0.01

    A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access…

  • CVE-2023-44195MedOct 13, 2023
    risk 0.35cvss 5.4epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the NetworkStack agent daemon (nsagentd) of Juniper Networks Junos OS Evolved allows an unauthenticated network based attacker to cause limited impact to the availability of the system. If…

  • CVE-2022-22177MedJan 19, 2022
    risk 0.35cvss 5.3epss 0.01

    A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impacts any version of…

  • CVE-2021-31386MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Networks Junos OS 12.3 versions prior to…

  • CVE-2021-31380MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to…

  • CVE-2021-31371MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an QFX5000 Series switch, leaking configuration information such as heartbeats, kernel versions, etc.…

  • CVE-2021-31369MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated network attacker to cause a partial Denial of Service (DoS) with a high rate of specific traffic. If a Class of…

  • CVE-2021-31361MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CPU utilization by…

  • CVE-2021-31352MedOct 19, 2021
    risk 0.35cvss 5.3epss 0.01

    An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers, which could allow a remote attacker to obtain sensitive information. A remote attacker with read and write access to network data…

  • CVE-2021-0294MedJul 15, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Juniper Networks Junos OS, which only affects the release 18.4R2-S5, where a function is inconsistently implemented on Juniper Networks Junos QFX5000 Series and EX4600 Series, and if "storm-control enhanced" is configured, can lead to the enhanced storm…

  • CVE-2021-0273MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960 devices with affected Trio line cards allows an attacker to exploit an interdependency in…

  • CVE-2021-0229MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker to cause MQTT server to crash and restart leading to a Denial of Service (DoS) by sending a stream of specific packets. A Juniper…

  • CVE-2020-1680MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.01

    On Juniper Networks MX Series with MS-MIC or MS-MPC card configured with NAT64 configuration, receipt of a malformed IPv6 packet may crash the MS-PIC component on MS-MIC or MS-MPC. This issue occurs when a multiservice card is translating the malformed IPv6 packet to IPv4…

  • CVE-2020-1665MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.01

    On Juniper Networks MX Series and EX9200 Series, in a certain condition the IPv6 Distributed Denial of Service (DDoS) protection might not take affect when it reaches the threshold condition. The DDoS protection allows the device to continue to function while it is under DDoS…

  • CVE-2020-1661MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.01

    On Juniper Networks Junos OS devices configured as a DHCP forwarder, the Juniper Networks Dynamic Host Configuration Protocol Daemon (jdhcp) process might crash when receiving a malformed DHCP packet. This issue only affects devices configured as DHCP forwarder with forward-only…

  • CVE-2020-1655MedJul 17, 2020
    risk 0.35cvss 5.3epss 0.01

    When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of large packets…

  • CVE-2020-1628MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration information such as heartbeats, kernel versions, etc. out to…

  • CVE-2020-1616MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remote attacker to perform multiple login…

  • CVE-2020-1606MedJan 15, 2020
    risk 0.35cvss 5.4epss 0.01

    A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by…

  • CVE-2020-1601MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    Certain types of malformed Path Computation Element Protocol (PCEP) packets when received and processed by a Juniper Networks Junos OS device serving as a Path Computation Client (PCC) in a PCEP environment using Juniper's path computational element protocol daemon (pccd)…

  • CVE-2019-0065MedOct 9, 2019
    risk 0.35cvss 5.3epss 0.01

    On MX Series, when the SIP ALG is enabled, receipt of a certain malformed SIP packet may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sending a crafted SIP packet, an attacker can repeatedly bring down MS-PIC on MS-MIC/MS-MPC causing a sustained Denial of…

  • CVE-2019-0027MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative…

  • CVE-2019-0026MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to…

  • CVE-2019-0025MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user…

  • CVE-2019-0024MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user…

  • CVE-2019-0023MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to…

  • CVE-2019-0018MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user…

  • CVE-2019-0015MedJan 15, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due to an error in token…

  • CVE-2019-0005MedJan 15, 2019
    risk 0.35cvss 5.3epss 0.01

    On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet filtering is unaffected by this…

  • CVE-2018-0062MedOct 10, 2018
    risk 0.35cvss 5.3epss 0.02

    A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service which may prevent other users to authenticate or to perform J-Web operations. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to…

  • CVE-2018-0061MedOct 10, 2018
    risk 0.35cvss 5.3epss 0.02

    A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81 on SRX Series; 12.3…

  • CVE-2018-0060MedOct 10, 2018
    risk 0.35cvss 5.3epss 0.01

    An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of Service to the dcd process and interfaces and connected clients when the Junos device is requesting an IP address for itself.…

  • CVE-2018-0059MedOct 10, 2018
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative…

  • CVE-2018-0034MedJul 11, 2018
    risk 0.35cvss 5.3epss 0.02

    A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending a crafted IPv6 packet to the system. This issue is limited to systems which receives IPv6 DHCP packets on a system configured for…

  • CVE-2018-0031MedJul 11, 2018
    risk 0.35cvss 5.3epss 0.01

    Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP packets must be encapsulated and meet a very specific packet format to be classified in a way that bypasses IP firewall filter rules. The packets themselves…

  • CVE-2018-0019MedApr 11, 2018
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the mib2d process to crash resulting in a denial of service condition (DoS) for the SNMP subsystem. While a mib2d process crash can disrupt the network monitoring…

  • CVE-2018-0011MedJan 10, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management…

  • CVE-2018-0009MedJan 10, 2018
    risk 0.35cvss 5.4epss 0.01

    On Juniper Networks SRX series devices, firewall rules configured to match custom application UUIDs starting with zeros can match all TCP traffic. Due to this issue, traffic that should have been blocked by other rules is permitted to flow through the device resulting in a…

  • CVE-2017-10621MedOct 13, 2017
    risk 0.35cvss 5.3epss 0.02

    A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9;…

  • CVE-2017-10616MedOct 13, 2017
    risk 0.35cvss 5.3epss 0.01

    The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be…

  • CVE-2017-10614MedOct 13, 2017
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption denial of service attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 12.1X46 prior to…

  • CVE-2017-10604MedJul 17, 2017
    risk 0.35cvss 5.3epss 0.01

    When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device is in cluster mode, and a cluster sync or…

  • CVE-2017-2311MedMay 30, 2017
    risk 0.35cvss 5.3epss 0.01

    On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.

  • CVE-2017-2310MedMay 30, 2017
    risk 0.35cvss 5.3epss 0.01

    A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.

  • CVE-2017-2340MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.02

    On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and destined to M/MX…

  • CVE-2017-2324MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.02

    A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.

Page 18 of 23