Vulnerabilidades en Juniper Networks

893 resultados
Análisis Vexday

Com 893 CVEs catalogadas e 7 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração de dispositivos Juniper Networks está 1,7× acima da média geral do catálogo, o que indica risco operacional elevado para organizações que dependem dessas soluções. A CVE mais crítica em exploração ativa no momento é CVE-2023-36846, com escore EPSS de 0,9421 — valor que sinaliza altíssima probabilidade de exploração em curto prazo e deve concentrar esforços imediatos de remediação. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), aponta para uma fragilidade estrutural de tratamento de erros que tende a se manifestar em múltiplos componentes. Com 38 CVEs de severidade crítica, 4 com prova de conceito pública disponível e 27 vulnerabilidades surgidas nos últimos 90 dias, o ritmo de exposição recente exige monitoramento contínuo e priorização ativa de patches.

CVE-2025-59960MEDIUMJunos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP serverEPSS 0.2%CVE-2025-52985MEDIUMJunos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 entries it's not matchingEPSS 0.2%CVE-2025-21600HIGHJunos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crashEPSS 0.2%CVE-2021-0235HIGHJunos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series: In a multi-tenant environment, a tenant host administrator may configure logical firewall isolation affecting other tenant networksEPSS 0.2%CVE-2021-0246HIGHJunos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3: In a multi-tenant environment, a tenant host administrator may be able to jailbreak out of their network impacting other tenant networks or gather information from other networks.EPSS 0.2%CVE-2021-31359HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerabilityEPSS 0.2%CVE-2026-21909HIGHJunos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crashEPSS 0.2%CVE-2021-0238MEDIUMJunos OS: MX Series: Executing CLI command repetitively may cause the system to run out of disk spaceEPSS 0.2%CVE-2025-21593HIGHJunos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crashEPSS 0.2%CVE-2025-21602HIGHJunos OS and Junos OS Evolved: Receipt of specially crafted BGP update packet causes RPD crashEPSS 0.2%CVE-2024-39527MEDIUMJunos OS: SRX Series: Low privileged user able to access sensitive information on file systemEPSS 0.2%CVE-2019-0069MEDIUMJunos OS: vSRX, SRX1500, SRX4K, ACX5K, EX4600, QFX5100, QFX5110, QFX5200, QFX10K and NFX Series: console management port device authentication credentials are logged in clear textEPSS 0.2%CVE-2026-21919HIGHJunos OS and Junos OS Evolved: A high frequency of connecting and disconnecting NETCONF sessions causes management unavailabilityEPSS 0.2%CVE-2024-39536MEDIUMJunos OS and Junos OS Evolved: Flaps of BFD sessions with authentication cause a ppmd memory leakEPSS 0.2%CVE-2022-22189HIGHContrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authenticationEPSS 0.2%CVE-2026-21911HIGHJunos OS Evolved: Flapping management interface causes MAC learning on label-switched interfaces to stopEPSS 0.2%CVE-2022-22193MEDIUMJunos OS and Junos OS Evolved: In a BGP rib-sharding scenario when a certain CLI command is executed the rpd process might crashEPSS 0.2%CVE-2024-39539MEDIUMJunos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crashEPSS 0.2%CVE-2024-39512HIGHJunos OS Evolved: User is not logged out when the console cable is disconnectedEPSS 0.2%CVE-2025-59989MEDIUMJunos Space: Device Discovery page is vulnerable to reflected cross-site script injectionEPSS 0.2%