Vulnerabilities in Juniper Networks

915 results
Vexday analysis

Com 893 CVEs catalogadas e 7 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração de dispositivos Juniper Networks está 1,7× acima da média geral do catálogo, o que indica risco operacional elevado para organizações que dependem dessas soluções. A CVE mais crítica em exploração ativa no momento é CVE-2023-36846, com escore EPSS de 0,9421 — valor que sinaliza altíssima probabilidade de exploração em curto prazo e deve concentrar esforços imediatos de remediação. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), aponta para uma fragilidade estrutural de tratamento de erros que tende a se manifestar em múltiplos componentes. Com 38 CVEs de severidade crítica, 4 com prova de conceito pública disponível e 27 vulnerabilidades surgidas nos últimos 90 dias, o ritmo de exposição recente exige monitoramento contínuo e priorização ativa de patches.

CVE-2019-0053HIGHJunos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflowEPSS 0.6%CVE-2019-0054MEDIUMJunos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.EPSS 0.6%CVE-2024-21611HIGHJunos OS and Junos OS Evolved: In a jflow scenario continuous route churn will cause a memory leak and eventually an rpd crashEPSS 0.6%CVE-2024-47490HIGHJunos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhaustedEPSS 0.6%CVE-2023-44182HIGHJunos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operationsEPSS 0.6%CVE-2020-1675HIGHJuniper Networks Mist Cloud UI: SAML authentication certificate vulnerability.EPSS 0.6%CVE-2024-30401HIGHJunos OS: MX Series and EX9200-15C: Stack-based buffer overflow in aftmanEPSS 0.6%CVE-2017-2342HIGHSRX Series: MACsec failure to report errorsEPSS 0.6%CVE-2024-21598HIGHJunos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crashEPSS 0.6%CVE-2023-28968MEDIUMJunos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail openEPSS 0.6%CVE-2017-10620HIGHSRX Series: Antivirus updates are downloaded without verificationEPSS 0.6%CVE-2023-28962MEDIUMJunos OS: Unauthenticated access vulnerability in J-WebEPSS 0.6%CVE-2023-22396HIGHJunos OS: Receipt of crafted TCP packets destined to the device results in MBUF leak leading to a Denial of Service (DoS)EPSS 0.6%CVE-2018-0029MEDIUMJunos OS: Kernel crash (vmcore) during broadcast storm after enabling 'monitor traffic interface fxp0'EPSS 0.6%CVE-2021-0247MEDIUMJunos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration.EPSS 0.6%CVE-2024-21606HIGHJunos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crashEPSS 0.6%CVE-2026-21906HIGHJunos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crashEPSS 0.6%CVE-2022-22156MEDIUMJunos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URLEPSS 0.5%CVE-2023-36843HIGHJunos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabledEPSS 0.5%CVE-2021-0253HIGHJunos OS: NFX Series: Local Command Execution Vulnerability in JDMD Leads to Privilege EscalationEPSS 0.5%