Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2020-1630

Published Apr 8, 2020

A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Virtual Chassis (VC) or high-availability cluster may allow a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1629

Published Apr 8, 2020

A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION mes…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1628

Published Apr 8, 2020

Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1627

Published Apr 8, 2020

A vulnerability in Juniper Networks Junos OS on vMX and MX150 devices may allow an attacker to cause a Denial of Service (DoS) by sending specific packets requiring special proces…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1625

Published Apr 8, 2020

The kernel memory usage represented as "temp" via 'show system virtual-memory' may constantly increase when Integrated Routing and Bridging (IRB) is configured with multiple under…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1619

Published Apr 8, 2020

A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine (NG-RE), allows a local authen…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1618

Published Apr 8, 2020

On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue migh…

CVSS 6.3 · Medium

CVE-2020-1615

Published Apr 8, 2020

The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the adm…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1614

Published Apr 8, 2020

A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to take control of the vSR…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6447

Published Feb 11, 2020

Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Juno…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6448

Published Jan 15, 2020

Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restrictions and execute arbitrary Python code via vectors invol…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1609

Published Jan 15, 2020

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1608

Published Jan 15, 2020

Receipt of a specific MPLS or IPv6 packet on the core facing interface of an MX Series device configured for Broadband Edge (BBE) service may trigger a kernel crash (vmcore), caus…

CVSS 7.5 · High

CVE-2020-1605

Published Jan 15, 2020

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1603

Published Jan 15, 2020

Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. I…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1602

Published Jan 15, 2020

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 526-550 of 786 CVEsPage 22 of 32