Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2020-1660

Published Oct 16, 2020

When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiser…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-1657

Published Oct 16, 2020

On SRX Series devices, a vulnerability in the key-management-daemon (kmd) daemon of Juniper Networks Junos OS allows an attacker to spoof packets targeted to IPSec peers before a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1656

Published Oct 16, 2020

The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vulnerability which will result…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1655

Published Jul 17, 2020

When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and…

CVSS 5.3 · Medium

CVE-2020-1654

Published Jul 17, 2020

On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS)…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-1653

Published Jul 17, 2020

On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the sy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1651

Published Jul 17, 2020

On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE) on the line card to crash and…

CVSS 6.5 · Medium

CVE-2020-1650

Published Jul 17, 2020

On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific packets may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sendi…

CVSS 7.5 · High

CVE-2020-1649

Published Jul 17, 2020

When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and…

CVSS 7.5 · High

CVE-2020-1647

Published Jul 17, 2020

On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remo…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-1646

Published Jul 17, 2020

On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1645

Published Jul 17, 2020

When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiser…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1643

Published Jul 17, 2020

Execution of the "show ospf interface extensive" or "show ospf interface detail" CLI commands on a Juniper Networks device running Junos OS may cause the routing protocols process…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1641

Published Jul 17, 2020

A Race Condition vulnerability in Juniper Networks Junos OS LLDP implementation allows an attacker to cause LLDP to crash leading to a Denial of Service (DoS). This issue occurs w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1640

Published Jul 17, 2020

An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1631

Published May 4, 2020

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisionin…

CVSS 8.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-1632

Published Apr 15, 2020

In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to o…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1633

Published Apr 9, 2020

Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG)…

CVSS 7.4 · High

CVE-2020-1639

Published Apr 8, 2020

When an attacker sends a specific crafted Ethernet Operation, Administration, and Maintenance (Ethernet OAM) packet to a target device, it may improperly handle the incoming malfo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1637

Published Apr 8, 2020

A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy.…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 786 CVEsPage 21 of 32