imPC@ndo IT

Juniper vulnerabilities

1105 CVE

CVE-2022-22153
High 7.5

An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 allows an unauthenticated networ…

juniper junos
0.01EPSS
CVE-2019-0016
Medium 6.5

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected rel…

juniper junos_space
0.01EPSS
CVE-2021-0278
High 8.8

An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S…

juniper junos
0.01EPSS
CVE-2022-22190
High 7.4

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature…

juniper paragon_active_assurance_control_center
0.01EPSS
CVE-2016-4931
Medium 6.5

XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.

juniper junos_space
0.01EPSS
CVE-2017-10623
High 7.1

Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks…

juniper junos_space
0.01EPSS
CVE-2021-0263
Medium 5.9

A Data Processing vulnerability in the Multi-Service process (multi-svcs) on the FPC of Juniper Networks Junos OS on the PTX Series routers may lead to the process becoming unresponsive, ultimately affecting traffic forwarding, allowing an attacker to cause a …

juniper junos
0.01EPSS
CVE-2018-0003
Medium 6.5

A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial …

juniper junos
0.01EPSS
CVE-2024-21620
High 8.8

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker…

juniper junos
0.01EPSS
CVE-2021-0260
High 7.3

An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Contr…

juniper junos
0.01EPSS
CVE-2020-1676
High 7.2

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security cont…

juniper mist_cloud_ui
0.01EPSS
CVE-2022-22198
High 7.5

An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Servi…

juniper junos
0.01EPSS
CVE-2017-10611
Medium 6.5

If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE…

juniper junos
0.01EPSS
CVE-2024-21619
Medium 5.3

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based a…

juniper junos
0.01EPSS
CVE-2020-1607
High 7.5

Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue aff…

juniper junos
0.01EPSS
CVE-2021-0266
High 8.1

The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on …

juniper junos
0.01EPSS
CVE-2017-10604
Medium 5.3

When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device is in cluster mode, an…

juniper junos
0.01EPSS
CVE-2021-0226
High 7.1

On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial…

juniper junos_os_evolved
0.01EPSS
CVE-2021-0269
High 8.8

The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device when a user is authenticated to J-Web. An attacker may be able to supersede exis…

juniper junos
0.01EPSS
CVE-2021-31350
High 7.5

An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root…

juniper junos · juniper junos_os_evolved
0.01EPSS
CVE-2019-0041
High 8.6

On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 versions prior to 18.2R1-…

juniper junos
0.01EPSS
CVE-2021-31356
High 7.8

A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the curre…

juniper junos_os_evolved
0.01EPSS
CVE-2018-0047
High 8.0

A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user…

juniper junos_space
0.01EPSS
CVE-2021-39532
Medium 6.5

An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service.

juniper libslax
0.01EPSS
CVE-2021-0268
High 8.8

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device …

juniper junos
0.01EPSS