Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Junos OS — Vulnerabilities & Security Advisories 660

All 660 CVE vulnerabilities found in Junos OS, with AI-generated Chinese analysis, references, and POCs.

This page details the vulnerability aggregation for Juniper Networks’ Junos OS, focusing on Common Weakness Enumerations (CWE) associated with this specific network operating system. It serves as a centralized resource for security professionals to monitor the stability and security posture of Juniper’s flagship software suite used in routers, switches, and other enterprise infrastructure devices. The content on this page compiles historical and recent vulnerability data affecting Junos OS, encompassing a broad time range from early releases to the most current updates. The collection includes weaknesses related to memory corruption, privilege escalation, input validation failures, and security configuration bypasses. By aggregating these findings, the page aims to provide a comprehensive view of the evolving threat landscape specific to Juniper’s software environment, allowing users to see trends in how different types of weaknesses have been identified and remediated over time. Here, you can track a vendor's advisories by navigating through release notes and security bulletins linked to specific versions. You can also understand a weakness class by examining how specific CWEs manifest within the context of network device firmware and software. Additionally, the page allows you to look up a product's vulnerability history, providing insights into the frequency and severity of past security incidents. This structured approach helps administrators prioritize patching efforts and assess the risk profile of their deployed Juniper equipment without needing to sift through disjointed sources. The focus remains strictly on factual reporting of vulnerabilities to support informed decision-making regarding network security maintenance and compliance.

Vendor: Juniper Networks

CVE IDTitleCVSSSeverityPublished
CVE-2023-44188 Junos OS: jkdsd crash due to multiple telemetry requests CWE-367 5.3 Medium2023-10-11
CVE-2023-44186 Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor CWE-755 7.5 High2023-10-11
CVE-2023-36851 Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files CWE-306 5.3 Medium2023-09-26
CVE-2023-4481 Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481) CWE-20 7.5 High2023-08-31
CVE-2023-36846 Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files CWE-306 5.3 Medium2023-08-17
CVE-2023-36845 Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable CWE-473 9.8 Critical2023-08-17
CVE-2023-36844 Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables CWE-473 5.3 Medium2023-08-17
CVE-2023-36847 Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files CWE-306 5.3 Medium2023-08-17
CVE-2023-36850 Junos OS: MX Series: An MPC will crash upon receipt of a malformed CFM packet. CWE-1285 6.5 Medium2023-07-14
CVE-2023-36849 Junos OS and Junos OS Evolved: The l2cpd will crash when a malformed LLDP packet is received CWE-703 6.5 Medium2023-07-14
CVE-2023-36848 Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet CWE-232 6.5 Medium2023-07-14
CVE-2023-36840 Junos OS and Junos OS Evolved: An rpd crash occurs when a specific L2VPN command is run CWE-617 5.5 Medium2023-07-14
CVE-2023-36836 Junos OS and Junos OS Evolved: In a MoFRR scenario an rpd core may be observed when a low privileged CLI command is executed CWE-908 4.7 Medium2023-07-14
CVE-2023-36835 Junos OS: QFX10000 Series: All traffic will be dropped after a specific valid IP packet has been received which needs to be routed over a VXLAN tunnel CWE-754 7.5 High2023-07-14
CVE-2023-36834 Junos OS: SRX 4600 and SRX 5000 Series: The receipt of specific genuine packets by SRXes configured for L2 transparency will cause a DoS CWE-372 6.5 Medium2023-07-14
CVE-2023-28985 SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received CWE-1286 7.5 High2023-07-14
CVE-2023-36838 Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command CWE-125 5.5 Medium2023-07-14
CVE-2023-36832 Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface CWE-755 7.5 High2023-07-14
CVE-2023-36831 Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied CWE-703 7.5 High2023-07-14
CVE-2023-0026 2023-06: Out-of-Cycle Security Bulletin: Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute CWE-20 7.5 High2023-06-21
CVE-2023-28974 Junos OS: MX Series: In a BBE scenario upon receipt of specific malformed packets from subscribers the process bbe-smgd will crash CWE-754 7.4 High2023-04-17
CVE-2023-28984 Junos OS: QFX Series: The PFE may crash when a lot of MAC addresses are being learned and aged CWE-362 5.3 Medium2023-04-17
CVE-2023-28982 Junos OS and Junos OS Evolved: In a BGP rib sharding scenario when a route is frequently updated an rpd memory leak will occur CWE-401 7.5 High2023-04-17
CVE-2023-28981 Junos OS and Junos OS Evolved: If malformed IPv6 router advertisements are received, memory corruption will occur which causes an rpd crash CWE-20 6.5 Medium2023-04-17
CVE-2023-28980 Junos OS and Junos OS Evolved: In a BGP rib sharding scenario an rpd crash will happen shortly after a specific CLI command is issued CWE-416 5.5 Medium2023-04-17
CVE-2023-28979 Junos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check fails CWE-754 4.7 Medium2023-04-17
CVE-2023-28976 Junos OS: MX Series: If a specific traffic rate goes above the DDoS threshold it will lead to an FPC crash CWE-754 7.5 High2023-04-17
CVE-2023-28967 Junos OS and Junos OS Evolved: An attacker sending genuine BGP packets causes an RPD crash 7.5 High2023-04-17
CVE-2023-28964 Junos OS and Junos OS Evolved: Malformed BGP flowspec update causes RPD crash CWE-130 7.5 High2023-04-17
CVE-2023-28965 Junos OS: QFX10002: Failure of storm control feature may lead to Denial of Service CWE-703 6.5 Medium2023-04-17

All 660 known CVE vulnerabilities affecting Junos OS with full Chinese analysis, references, and POCs where available.