Vulnerability index

Browse CVEs

1,019 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Junos HIGH 7.4
CVE-2019-0054

An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos O…

Mitigation only
Fix from $1,950 2019-10-09
Libslax MEDIUM 6.5
CVE-2019-1010232

Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1, 2018) is affected by: Buffer …

No fix yet
Fix from $1,600 2019-07-22
Junos HIGH 7.5
CVE-2019-0049

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a certain sequence of BGP session r…

Patch available
Fix from $1,950 2019-07-11
Junos HIGH 7.5
CVE-2019-0052

The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterp…

Patch available
Fix from $1,950 2019-07-11
Junos MEDIUM 6.5
CVE-2019-0046

A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) …

Patch available
Fix from $1,600 2019-07-11
Junos MEDIUM 5.8
CVE-2019-0048

On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has hig…

Patch available
Fix from $1,600 2019-07-11
Junos HIGH 7.5
CVE-2019-0043

In MPLS environments, receipt of a specific SNMP packet may cause the routing protocol daemon (RPD) process to crash and restart. By continuously sen…

Mitigation only
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0044

Receipt of a specific packet on the out-of-band management interface fxp0 may cause the system to crash and restart (vmcore). By continuously sending…

Patch available
Fix from $1,950 2019-04-10
Junos CRITICAL 9.8
CVE-2019-0008

A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC)…

Fix: 15.1x53-d235 / 17.1r3+
Fix from $2,300 2019-04-10
Junos CRITICAL 9.8
CVE-2019-0036

When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silen…

Mitigation only
Fix from $2,300 2019-04-10
Junos CRITICAL 9.1
CVE-2019-0040

On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dro…

Mitigation only
Fix from $2,300 2019-04-10
Junos HIGH 8.6
CVE-2019-0041

On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The devic…

Mitigation only
Fix from $1,950 2019-04-10
Junos HIGH 8.1
CVE-2019-0039

If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may a…

Fix: 14.1x53-d49 / 15.1f6-s12+
Fix from $1,950 2019-04-10
Service Insight HIGH 7.8
CVE-2019-0032

A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authe…

Fix: 18.1r1+
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0019

When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd rest…

Mitigation only
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0028

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote p…

Mitigation only
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0031

Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcp…

Fix: 17.4r2 / 18.1r2+
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0033

A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a D…

Fix: 12.1x46-d71 / 12.3x48-d50+
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0037

In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solic…

Mitigation only
Fix from $1,950 2019-04-10
Junos MEDIUM 6.8
CVE-2019-0035

When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed usi…

Mitigation only
Fix from $1,600 2019-04-10
Junos MEDIUM 6.5
CVE-2019-0038

Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition du…

Mitigation only
Fix from $1,600 2019-04-10
Advanced Threat Prevention Firmware HIGH 7.2
CVE-2019-0030

Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents. This issue affects Jun…

Fix: 5.0.3+
Fix from $1,950 2019-01-15
Junos CRITICAL 10.0
CVE-2019-0007

The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible…

Mitigation only
Fix from $2,300 2019-01-15
Junos CRITICAL 9.8
CVE-2019-0006EPSS 5%

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on…

Mitigation only
Fix from $2,300 2019-01-15
Advanced Threat Prevention CRITICAL 9.8
CVE-2019-0020

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installat…

Fix: 5.0.3+
Fix from $2,300 2019-01-15
Advanced Threat Prevention CRITICAL 9.8
CVE-2019-0022

Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installati…

Fix: 5.0.3+
Fix from $2,300 2019-01-15
Junos Space HIGH 8.8
CVE-2019-0017

The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of maliciou…

Mitigation only
Fix from $1,950 2019-01-15
Advanced Threat Prevention HIGH 7.8
CVE-2019-0029

Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the …

Fix: 5.0.3+
Fix from $1,950 2019-01-15
Junos HIGH 7.5
CVE-2019-0010

An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an…

Mitigation only
Fix from $1,950 2019-01-15
Junos HIGH 7.5
CVE-2019-0012

A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker to craft a specific BGP messag…

Patch available
Fix from $1,950 2019-01-15