Vulnerabilities in Juniper Networks

915 results
Vexday analysis

Com 893 CVEs catalogadas e 7 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração de dispositivos Juniper Networks está 1,7× acima da média geral do catálogo, o que indica risco operacional elevado para organizações que dependem dessas soluções. A CVE mais crítica em exploração ativa no momento é CVE-2023-36846, com escore EPSS de 0,9421 — valor que sinaliza altíssima probabilidade de exploração em curto prazo e deve concentrar esforços imediatos de remediação. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), aponta para uma fragilidade estrutural de tratamento de erros que tende a se manifestar em múltiplos componentes. Com 38 CVEs de severidade crítica, 4 com prova de conceito pública disponível e 27 vulnerabilidades surgidas nos últimos 90 dias, o ritmo de exposição recente exige monitoramento contínuo e priorização ativa de patches.

CVE-2017-2312On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing EnginEPSS 1.6%CVE-2018-0018HIGHSRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.EPSS 1.6%CVE-2019-0044HIGHJunos OS: SRX5000 series: Kernel crash (vmcore) upon receipt of a specific packet on fxp0 interfaceEPSS 1.6%CVE-2019-0047HIGHJunos OS: Persistent XSS vulnerability in J-WebEPSS 1.6%CVE-2020-1673HIGHJunos OS: Reflected Cross-site Scripting vulnerability in J-Web and web based (HTTP/HTTPS) servicesEPSS 1.6%CVE-2018-0002HIGHMX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.EPSS 1.5%CVE-2019-0049HIGHJunos OS: RPD process crashes when BGP peer restartsEPSS 1.5%CVE-2017-10618MEDIUMJunos: RPD core due to BGP UPDATE with malformed optional transitive attributesEPSS 1.5%CVE-2021-31385HIGHJunos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to rootEPSS 1.5%CVE-2022-22188HIGHJunos OS: QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series: When storm control profiling is enabled and a device is under an active storm, a Heap-based Buffer Overflow in the PFE will cause a device to hang.EPSS 1.5%CVE-2018-0019MEDIUMJunos: Denial of service vulnerability in SNMP MIB-II subagent daemon (mib2d).EPSS 1.5%CVE-2025-21589CRITICALSession Smart Router, Session Smart Conductor, WAN Assurance Router: API Authentication Bypass vulnerabilityEPSS 1.5%CVE-2023-28983HIGHJunos OS Evolved: Shell Injection vulnerability in the gNOI serverEPSS 1.5%CVE-2017-2321A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unpEPSS 1.5%CVE-2018-0040CRITICALContrail Service Orchestration: hardcoded cryptographic certificates and keysEPSS 1.4%CVE-2020-1616MEDIUMJATP Series: JATP Is susceptible to slow brute force attacks on the SSH service.EPSS 1.4%CVE-2018-0058MEDIUMMX Series: In BBE configurations, receipt of a crafted IPv6 exception packet causes a Denial of ServiceEPSS 1.4%CVE-2020-1603HIGHJunos OS: Improper handling of specific IPv6 packets sent by clients eventually kernel crash (vmcore) the device.EPSS 1.4%CVE-2020-1686HIGHJunos OS: Kernel crash (vmcore) upon receipt of a malformed IPv6 packet.EPSS 1.4%CVE-2020-1640HIGHJunos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.EPSS 1.4%