Skip to main content

Vendor archive

juniper CVEs

Beta · best-effort

1,105 CVEs tagged to vendor juniper65 Critical, 543 High, 489 Medium, 8 Low, 0 Unrated.

CVE-2021-0281

Published Jul 15, 2021

On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0279

Published Jul 15, 2021

Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging services of RabbitMQ are used when…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0278

Published Jul 15, 2021

An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target devic…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0277

Published Jul 15, 2021

An Out-of-bounds Read vulnerability in the processing of specially crafted LLDP frames by the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0276

Published Jul 15, 2021

A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending spe…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-0270

Published Apr 22, 2021

On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Junipe…

CVSS 7.5 · High

CVE-2021-0269

Published Apr 22, 2021

The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0268

Published Apr 22, 2021

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0267

Published Apr 22, 2021

An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Serv…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0266

Published Apr 22, 2021

The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment thro…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0265

Published Apr 22, 2021

An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on the host running the AppFormi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0264

Published Apr 22, 2021

A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX1…

CVSS 5.9 · Medium

CVE-2021-0262

Published Apr 22, 2021

Through routine static code analysis of the Juniper Networks Junos OS software codebase, the Secure Development Life Cycle team identified a Use After Free vulnerability in PFE pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0260

Published Apr 22, 2021

An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0258

Published Apr 22, 2021

A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0257

Published Apr 22, 2021

On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IRB) interfaces are configured a…

CVSS 6.5 · Medium

CVE-2021-0256

Published Apr 22, 2021

A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 551-575 of 1,105 CVEsPage 23 of 45