Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2019-0047

Published Oct 9, 2019

A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0053

Published Jul 11, 2019

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec rest…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0049

Published Jul 11, 2019

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a certain sequence of BGP session restart on a remote peer that h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0046

Published Jul 11, 2019

A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the EX4300 when specific va…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0041

Published Apr 10, 2019

On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such tra…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0040

Published Apr 10, 2019

On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information le…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-0039

Published Apr 10, 2019

If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-forc…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0037

Published Apr 10, 2019

In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solicit messages received from a DH…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0036

Published Apr 10, 2019

When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is iss…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-0035

Published Apr 10, 2019

When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0033

Published Apr 10, 2019

A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a Denial of Service (DoS). This i…

CVSS 7.5 · High

CVE-2019-0031

Published Apr 10, 2019

Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcpd daemon configured to respond…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0028

Published Apr 10, 2019

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful rest…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0019

Published Apr 10, 2019

When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0015

Published Jan 15, 2019

A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connect…

CVSS 5.4 · Medium

CVE-2019-0014

Published Jan 15, 2019

On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all interfaces to go down. By continu…

CVSS 7.5 · High

CVE-2019-0013

Published Jan 15, 2019

The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is received. While RPD restarts after a crash, repeated crashes can r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0012

Published Jan 15, 2019

A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker to craft a specific BGP message to cause the routing protoco…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 786 CVEsPage 24 of 32