Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Junos OS — Vulnerabilities & Security Advisories 660

All 660 CVE vulnerabilities found in Junos OS, with AI-generated Chinese analysis, references, and POCs.

This page details the vulnerability aggregation for Juniper Networks’ Junos OS, focusing on Common Weakness Enumerations (CWE) associated with this specific network operating system. It serves as a centralized resource for security professionals to monitor the stability and security posture of Juniper’s flagship software suite used in routers, switches, and other enterprise infrastructure devices. The content on this page compiles historical and recent vulnerability data affecting Junos OS, encompassing a broad time range from early releases to the most current updates. The collection includes weaknesses related to memory corruption, privilege escalation, input validation failures, and security configuration bypasses. By aggregating these findings, the page aims to provide a comprehensive view of the evolving threat landscape specific to Juniper’s software environment, allowing users to see trends in how different types of weaknesses have been identified and remediated over time. Here, you can track a vendor's advisories by navigating through release notes and security bulletins linked to specific versions. You can also understand a weakness class by examining how specific CWEs manifest within the context of network device firmware and software. Additionally, the page allows you to look up a product's vulnerability history, providing insights into the frequency and severity of past security incidents. This structured approach helps administrators prioritize patching efforts and assess the risk profile of their deployed Juniper equipment without needing to sift through disjointed sources. The focus remains strictly on factual reporting of vulnerabilities to support informed decision-making regarding network security maintenance and compliance.

Vendor: Juniper Networks

CVE IDTitleCVSSSeverityPublished
CVE-2019-0040 Junos OS: Specially crafted packets sent to port 111 on any interface triggers responses from the management interface CWE-200 8.2 -2019-04-10
CVE-2019-0001 Junos OS: MX Series: uncontrolled recursion and crash in Broadband Edge subscriber management daemon (bbe-smgd). CWE-674 7.5 -2019-01-15
CVE-2019-0002 Junos OS: EX2300 and EX3400 series: Certain stateless firewall filter rules might not take effect CWE-794 9.8 -2019-01-15
CVE-2019-0003 Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core. CWE-617 5.9 -2019-01-15
CVE-2019-0006 Junos OS: EX, QFX and MX series: Packet Forwarding Engine manager (FXPC) process crashes due to a crafted HTTP packet in a Virtual Chassis configuration CWE-908 9.8 -2019-01-15
CVE-2019-0007 Junos OS: vMX series: Predictable IP ID sequence numbers vulnerability 10.0 -2019-01-15
CVE-2019-0009 Junos OS: EX2300 and EX3400: High disk I/O operations may disrupt the communication between RE and PFE 5.5 -2019-01-15
CVE-2019-0010 Junos OS: SRX Series: Crafted HTTP traffic may cause UTM to consume all mbufs, leading to Denial of Service 7.5 -2019-01-15
CVE-2019-0011 Junos OS: Kernel crash after processing specific incoming packet to the out of band management interface (CVE-2019-0011) 6.5 -2019-01-15
CVE-2019-0012 Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message 7.5 -2019-01-15
CVE-2019-0013 Junos OS: RPD crash upon receipt of malformed PIM packet 7.5 -2019-01-15
CVE-2019-0014 Junos OS: QFX and PTX Series: FPC process crashes after J-Flow processes a malformed packet 7.5 -2019-01-15
CVE-2019-0015 Junos OS: SRX Series: Deleted dynamic VPN users are allowed to establish VPN connections until reboot 8.2 -2019-01-15
CVE-2018-0043 Junos OS: RPD daemon crashes upon receipt of specific MPLS packet 8.8 -2018-10-10
CVE-2018-0044 NFX Series: Insecure sshd configuration in Juniper Device Manager (JDM) and host OS 8.1 -2018-10-10
CVE-2018-0045 Junos OS: RPD daemon crashes due to receipt of specific Draft-Rosen MVPN control packet in Draft-Rosen MVPN configuration 9.8 -2018-10-10
CVE-2018-0048 Junos OS: Memory exhaustion denial of service vulnerability in Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support. CWE-400 7.5 -2018-10-10
CVE-2018-0049 Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash. 7.5 -2018-10-10
CVE-2018-0050 Junos OS: Receipt of a malformed MPLS RSVP packet leads to a Routing Protocols Daemon (RPD) crash. 7.5 -2018-10-10
CVE-2018-0051 Junos OS: Denial of Service vulnerability in MS-PIC, MS-MIC, MS-MPC, MS-DPC and SRX flow daemon (flowd) related to SIP ALG 5.9 -2018-10-10
CVE-2018-0052 Junos OS: Unauthenticated remote root access possible when RSH service is enabled 9.8 -2018-10-10
CVE-2018-0053 vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting. 6.8 -2018-10-10
CVE-2018-0054 QFX5000/EX4600 Series: Routing protocol flap upon receipt of high rate of Ethernet frames 7.1 -2018-10-10
CVE-2018-0055 Junos OS: jdhcpd process crash during processing of specially crafted DHCPv6 message 5.9 -2018-10-10
CVE-2018-0056 MX Series: L2ALD daemon may crash if a duplicate MAC is learned by two different interfaces 5.3 -2018-10-10
CVE-2018-0057 Junos OS: authd allows assignment of IP address requested by DHCP subscriber logging in with Option 50 (Requested IP Address) 9.6 -2018-10-10
CVE-2018-0058 MX Series: In BBE configurations, receipt of a crafted IPv6 exception packet causes a Denial of Service 7.5 -2018-10-10
CVE-2018-0060 Junos OS: Invalid IP/mask learned from DHCP server might cause device control daemon (dcd) process crash 5.9 -2018-10-10
CVE-2018-0061 Junos OS: Denial of service in telnetd 5.3 -2018-10-10
CVE-2018-0062 Junos OS: Denial of Service in J-Web 7.5 -2018-10-10

All 660 known CVE vulnerabilities affecting Junos OS with full Chinese analysis, references, and POCs where available.