Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Junos OS — Vulnerabilities & Security Advisories 660

All 660 CVE vulnerabilities found in Junos OS, with AI-generated Chinese analysis, references, and POCs.

This page details the vulnerability aggregation for Juniper Networks’ Junos OS, focusing on Common Weakness Enumerations (CWE) associated with this specific network operating system. It serves as a centralized resource for security professionals to monitor the stability and security posture of Juniper’s flagship software suite used in routers, switches, and other enterprise infrastructure devices. The content on this page compiles historical and recent vulnerability data affecting Junos OS, encompassing a broad time range from early releases to the most current updates. The collection includes weaknesses related to memory corruption, privilege escalation, input validation failures, and security configuration bypasses. By aggregating these findings, the page aims to provide a comprehensive view of the evolving threat landscape specific to Juniper’s software environment, allowing users to see trends in how different types of weaknesses have been identified and remediated over time. Here, you can track a vendor's advisories by navigating through release notes and security bulletins linked to specific versions. You can also understand a weakness class by examining how specific CWEs manifest within the context of network device firmware and software. Additionally, the page allows you to look up a product's vulnerability history, providing insights into the frequency and severity of past security incidents. This structured approach helps administrators prioritize patching efforts and assess the risk profile of their deployed Juniper equipment without needing to sift through disjointed sources. The focus remains strictly on factual reporting of vulnerabilities to support informed decision-making regarding network security maintenance and compliance.

Vendor: Juniper Networks

CVE IDTitleCVSSSeverityPublished
CVE-2021-0250 Junos OS and Junos OS Evolved: An attacker sending a specific crafted BGP update message will crash RPD 7.5 High2021-04-22
CVE-2021-0251 Junos OS: MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC: The BRAS Subscriber Services service activation portal is vulnerable to a Denial of Service (DoS) via malformed HTTP packets 8.6 High2021-04-22
CVE-2021-0249 Junos OS: SRX Series: A remote attacker may be able to cause a PFE buffer overflow to arbitrarily remotely execute code or commands on the target device with UTM enabled. 8.1 High2021-04-22
CVE-2021-0247 Junos OS: PTX Series, QFX Series: Due to a race condition input loopback firewall filters applied to interfaces may not operate even when listed in the running configuration. CWE-362 5.1 Medium2021-04-22
CVE-2021-0248 NFX Series: Hard-coded credentials allow an attacker to take control of any instance through administrative interfaces. CWE-798 10.0 Critical2021-04-22
CVE-2021-0246 Junos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3: In a multi-tenant environment, a tenant host administrator may be able to jailbreak out of their network impacting other tenant networks or gather information from other networks. 7.3 High2021-04-22
CVE-2021-0244 Junos OS: A race condition in the storm control profile may allow an attacker to cause a Denial of Service condition 7.4 High2021-04-22
CVE-2021-0245 Junos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges. CWE-798 7.8 High2021-04-22
CVE-2021-0243 Junos OS: EX4300: Stateless firewall policer fails to discard traffic CWE-241 4.7 Medium2021-04-22
CVE-2021-0241 Junos OS: Receipt of specific DHCPv6 packet may cause jdhcpd to crash and restart CWE-703 7.4 High2021-04-22
CVE-2021-0242 Junos OS: EX4300: FPC crash upon receipt of specific frames on an interface without L2PT or dot1x configured CWE-119 6.5 Medium2021-04-22
CVE-2021-0240 Junos OS: Receipt of malformed DHCPv6 packets causes jdhcpd to crash and restart. CWE-703 7.4 High2021-04-22
CVE-2021-0238 Junos OS: MX Series: Executing CLI command repetitively may cause the system to run out of disk space CWE-400 5.5 Medium2021-04-22
CVE-2021-0237 Junos OS: EX4300-MP/EX4600/EX4650/QFX5K Series: Packet Forwarding Engine manager (FXPC) process crashes when deployed in a Virtual Chassis (VC) configuration 6.5 Medium2021-04-22
CVE-2021-0235 Junos OS: SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series: In a multi-tenant environment, a tenant host administrator may configure logical firewall isolation affecting other tenant networks CWE-276 7.3 High2021-04-22
CVE-2021-0236 Junos OS: A specific BGP VPNv6 flowspec message causes routing protocol daemon (rpd) process to crash with a core. CWE-754 6.5 Medium2021-04-22
CVE-2021-0234 Junos OS: QFX5100-96S: DDoS protection does not work as expected. 5.8 Medium2021-04-22
CVE-2021-0233 Junos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets. CWE-794 7.5 High2021-04-22
CVE-2021-0231 Junos OS: SRX, vSRX Series: J-Web Path traversal vulnerability in SRX and vSRX Series leads to information disclosure. CWE-22 6.5 Medium2021-04-22
CVE-2021-0229 Junos OS: Receipt of specific packets could lead to Denial of Service in MQTT Server CWE-400 5.3 Medium2021-04-22
CVE-2021-0230 Junos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statistics CWE-400 7.5 High2021-04-22
CVE-2021-0228 Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment CWE-754 6.5 Medium2021-04-22
CVE-2021-0227 Junos OS: SRX Series: Denial of Service in J-Web upon receipt of crafted HTTP packets CWE-119 7.5 High2021-04-22
CVE-2021-0224 Junos OS: ANCPD core when hitting maximum-discovery-table-entries limit CWE-770 6.5 Medium2021-04-22
CVE-2021-0214 Junos OS: Denial of Service in ppmd upon receipt of malformed packet CWE-20 6.5 Medium2021-04-22
CVE-2021-0216 Junos OS: ACX5448, ACX710: BFD sessions might flap due to high rate of transit ARP packets 6.5 Medium2021-04-22
CVE-2021-0222 Junos OS: Upon receipt of certain protocol packets with invalid payloads a self-propagating Denial of Service may occur. 7.4 High2021-01-15
CVE-2021-0223 Junos OS: telnetd.real Local Privilege Escalation vulnerabilities in SUID binaries CWE-250 7.8 High2021-01-15
CVE-2021-0221 Junos OS: QFX Series: Traffic loop Denial of Service (DoS) upon receipt of specific IP multicast traffic CWE-703 6.5 Medium2021-01-15
CVE-2021-0219 Junos OS: Command injection vulnerability in 'request system software' CLI command CWE-78 6.7 Medium2021-01-15

All 660 known CVE vulnerabilities affecting Junos OS with full Chinese analysis, references, and POCs where available.