Vulnerabilities in Juniper Networks

893 results
Vexday analysis

Com 893 CVEs catalogadas e 7 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração de dispositivos Juniper Networks está 1,7× acima da média geral do catálogo, o que indica risco operacional elevado para organizações que dependem dessas soluções. A CVE mais crítica em exploração ativa no momento é CVE-2023-36846, com escore EPSS de 0,9421 — valor que sinaliza altíssima probabilidade de exploração em curto prazo e deve concentrar esforços imediatos de remediação. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), aponta para uma fragilidade estrutural de tratamento de erros que tende a se manifestar em múltiplos componentes. Com 38 CVEs de severidade crítica, 4 com prova de conceito pública disponível e 27 vulnerabilidades surgidas nos últimos 90 dias, o ritmo de exposição recente exige monitoramento contínuo e priorização ativa de patches.

CVE-2024-21601MEDIUMJunos OS: SRX Series: Due to an error in processing TCP events flowd will crashEPSS 0.5%CVE-2020-1651MEDIUMJunos OS: MX Series: PFE on the line card may crash due to memory leak.EPSS 0.5%CVE-2018-0008MEDIUMJunos OS: commit script may allow unauthenticated root login upon rebootEPSS 0.5%CVE-2021-0214MEDIUMJunos OS: Denial of Service in ppmd upon receipt of malformed packetEPSS 0.5%CVE-2022-22249MEDIUMJunos OS: MX Series: An FPC crash might be seen due to mac-moves within the same bridge domainEPSS 0.4%CVE-2025-52981HIGHJunos OS: SRX Series: Sequence of specific PIM packets causes a flowd crashEPSS 0.4%CVE-2022-22225MEDIUMJunos OS and Junos OS Evolved: In a BGP multipath scenario, when one of the contributing routes is flapping often and rapidly, rpd may crashEPSS 0.4%CVE-2022-22220MEDIUMJunos OS and Junos OS Evolved: Due to a race condition the rpd process can crash upon receipt of a BGP update message containing flow spec routeEPSS 0.4%CVE-2019-0032MEDIUMJunos Space Service Now and Service Insight: Organization username and password stored in plaintext in log files.EPSS 0.4%CVE-2025-52961HIGHJunos OS Evolved: PTX Series except PTX10003: An unauthenticated adjacent attacker sending specific valid traffic can cause a memory leak in cfmman leading to FPC crash and restartEPSS 0.4%CVE-2021-0209MEDIUMJunos OS Evolved: Receipt of certain valid BGP update packets from BGP peers may cause RPD to core when using REGEX.EPSS 0.4%CVE-2025-52946HIGHJunos OS and Junos OS Evolved: With traceoptions enabled, receipt of malformed AS PATH causes RPD crashEPSS 0.4%CVE-2025-52948HIGHJunos OS: Specific unknown traffic pattern causes FPC and system to crash when packet capturing is enabledEPSS 0.4%CVE-2024-30391MEDIUMJunos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performedEPSS 0.4%CVE-2026-21920HIGHJunos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crashEPSS 0.4%CVE-2024-39515HIGHJunos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crashEPSS 0.4%CVE-2024-39531HIGHJunos OS Evolved: ACX 7000 Series: Protocol specific DDoS configuration affects other protocolsEPSS 0.4%CVE-2024-39525HIGHJunos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crashEPSS 0.4%CVE-2017-10603HIGHJunos OS: Local XML Injection through CLI command can lead to privilege escalationEPSS 0.4%CVE-2022-22243MEDIUMJunos OS: XPath Injection vulnerability in J-WebEPSS 0.4%