VYPR

Vendor CVEs

Juniper Networks

All CVEs

1,117 total · sorted by risk
  • CVE-2013-6014CriOct 28, 2013
    risk 0.61cvss 9.3epss 0.01

    Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is enabled on an…

  • CVE-2025-59978CriOct 9, 2025
    risk 0.59cvss 9.0epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the…

  • CVE-2019-0040CriApr 10, 2019
    risk 0.59cvss 9.1epss 0.02

    On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information leak vulnerability, responses were being generated from the source address of the management interface…

  • CVE-2016-4929HigMar 20, 2017
    risk 0.58cvss 8.8epss 0.04

    Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.

  • CVE-2026-33785HigApr 9, 2026
    risk 0.57cvss 8.8epss 0.00

    A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring…

  • CVE-2025-13914HigApr 9, 2026
    risk 0.57cvss 8.7epss 0.00

    A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle…

  • CVE-2024-39565HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.  While an administrator is logged…

  • CVE-2024-21620HigJan 25, 2024
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute…

  • CVE-2023-28983HigApr 17, 2023
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects Juniper Networks…

  • CVE-2022-22182HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects: Juniper…

  • CVE-2021-31385HigOct 19, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in J-Web of Juniper Networks Junos OS allows any low-privileged authenticated attacker to elevate their privileges to root. This issue affects: Juniper Networks Junos OS 12.3 versions…

  • CVE-2021-31372HigOct 19, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3R3-S5; 18.4…

  • CVE-2021-39534HigSep 20, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow.

  • CVE-2021-39533HigSep 20, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow.

  • CVE-2021-39531HigSep 20, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow.

  • CVE-2021-0278HigJul 15, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S3 junos:19.4R1-S4…

  • CVE-2021-0277HigJul 15, 2021
    risk 0.57cvss 8.8epss 0.01

    An Out-of-bounds Read vulnerability in the processing of specially crafted LLDP frames by the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved may allow an attacker to cause a Denial of Service (DoS), or may lead to remote code execution…

  • CVE-2021-0275HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross-site Scripting (XSS) vulnerability in J-Web on Juniper Networks Junos OS allows an attacker to target another user's session thereby gaining access to the users session. The other user session must be active for the attack to succeed. Once successful, the attacker has…

  • CVE-2021-0269HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device when a user is authenticated to J-Web. An attacker may be able to supersede existing parameters,…

  • CVE-2021-0268HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration…

  • CVE-2021-0208HigJan 15, 2021
    risk 0.57cvss 8.8epss 0.01

    An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of…

  • CVE-2020-1673HigOct 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient Cross-Site Scripting (XSS) protection in Juniper Networks J-Web and web based (HTTP/HTTPS) services allows an unauthenticated attacker to hijack the target user's HTTP/HTTPS session and perform administrative actions on the Junos device as the targeted user. This…

  • CVE-2020-1656HigOct 16, 2020
    risk 0.57cvss 8.8epss 0.01

    The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vulnerability which will result in a Denial of Service (DoS) condition when a DHCPv6 client sends a specific DHPCv6 message allowing…

  • CVE-2020-1609HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute commands as root on the…

  • CVE-2020-1605HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute commands as root on the…

  • CVE-2019-0070HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.00

    An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This leads to the…

  • CVE-2019-0047HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos administrator to first perform certain diagnostic actions…

  • CVE-2019-0029HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.00

    Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the Splunk server. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

  • CVE-2018-0045HigOct 10, 2018
    risk 0.57cvss 8.8epss 0.01

    Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending the same specific Draft-Rosen MVPN control packet, an attacker can repeatedly crash the…

  • CVE-2018-0043HigOct 10, 2018
    risk 0.57cvss 8.8epss 0.01

    Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending specific MPLS packets, an attacker can repeatedly crash the RPD process causing a sustained Denial of Service.…

  • CVE-2018-0021HigApr 11, 2018
    risk 0.57cvss 8.8epss 0.01

    If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CAK) key are not configured, all remaining digits will be auto-configured to 0. Hence, Juniper devices configured with short MacSec keys are at risk to an…

  • CVE-2017-2341HigJul 17, 2017
    risk 0.57cvss 8.8epss 0.00

    An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users on the Junos OS instance to gain access to the host operating environment, and thus escalate privileges. Affected releases are…

  • CVE-2017-2306HigMay 30, 2017
    risk 0.57cvss 8.8epss 0.02

    On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.

  • CVE-2017-2305HigMay 30, 2017
    risk 0.57cvss 8.8epss 0.01

    On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.

  • CVE-2017-2332HigApr 24, 2017
    risk 0.57cvss 8.8epss 0.02

    An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment.

  • CVE-2016-4928HigMar 20, 2017
    risk 0.57cvss 8.8epss 0.01

    Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.

  • CVE-2016-1264HigApr 15, 2016
    risk 0.57cvss 8.8epss 0.02

    Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before…

  • CVE-2025-59968HigOct 9, 2025
    risk 0.56cvss 8.6epss 0.00

    A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface.  Tampering with this metadata can result in managed SRX Series devices permitting…

  • CVE-2021-0279HigJul 15, 2021
    risk 0.56cvss 8.6epss 0.01

    Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging services of RabbitMQ are used when coordinating operations and status information among Contrail services. An attacker with access to…

  • CVE-2021-0251HigApr 22, 2021
    risk 0.56cvss 8.6epss 0.01

    A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC allows an attacker to send malformed HTTP packets to the device thereby causing a Denial…

  • CVE-2021-0203HigJan 15, 2021
    risk 0.56cvss 8.6epss 0.01

    On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop…

  • CVE-2020-1632HigApr 15, 2020
    risk 0.56cvss 8.6epss 0.01

    In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of…

  • CVE-2020-1613HigApr 8, 2020
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the BGP FlowSpec implementation may cause a Juniper Networks Junos OS device to terminate an established BGP session upon receiving a specific BGP FlowSpec advertisement. The BGP NOTIFICATION message that terminates an established BGP session is sent toward…

  • CVE-2020-1603HigJan 15, 2020
    risk 0.56cvss 8.6epss 0.01

    Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which point a mbuf memory…

  • CVE-2019-0041HigApr 10, 2019
    risk 0.56cvss 8.6epss 0.01

    On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 versions prior to 18.2R1-S2, 18.2R2 on…

  • CVE-2017-10605HigJul 17, 2017
    risk 0.56cvss 8.6epss 0.02

    On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended…

  • CVE-2017-2321HigApr 24, 2017
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and…

  • CVE-2017-2317HigApr 24, 2017
    risk 0.56cvss 8.6epss 0.01

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential…

  • CVE-2025-59974HigOct 9, 2025
    risk 0.55cvss 8.4epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers…

  • CVE-2024-30381HigApr 12, 2024
    risk 0.55cvss 8.4epss 0.00

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a network-adjacent attacker with root access to a Test Agent Appliance the ability to access sensitive information about downstream…

Page 2 of 23