Juniper Security Vulnerabilities (CVEs)

Track 219 security vulnerabilities affecting Juniper products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

9 Critical
135 High
75 Medium
🔔 Get Alerts for Juniper
CVE-2023-36835 7.5

A vulnerability in Juniper Networks Junos OS on QFX10000 Series allows a network-based attacker to cause a persistent Denial of Service (DoS) by sendi...

Jul 14, 2023
CVE-2023-36832 7.5

An unauthenticated network attacker can send specific packets to Aggregated Multiservices (AMS) interfaces on vulnerable Juniper MX Series devices, ca...

Jul 14, 2023
CVE-2023-36831 7.5

A memory leak vulnerability in Juniper SRX Series firewalls with SSL Proxy and UTM Web-Filtering enabled causes gradual memory exhaustion when accessi...

Jul 14, 2023
CVE-2023-0026 7.5

An improper input validation vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated attackers to cause BGP session flaps and ...

Jun 21, 2023
CVE-2023-28971 7.2

This vulnerability allows attackers to bypass firewall rules that restrict communication between Test Agents and the Control Center in Juniper Paragon...

Apr 17, 2023
CVE-2023-28973 7.1

This CVE allows local authenticated attackers on Juniper Junos OS Evolved systems to execute administrative commands through the 'sysmanctl' shell com...

Apr 17, 2023
CVE-2023-28976 7.5

An unauthenticated network attacker can cause denial of service on Juniper MX Series routers by sending specific traffic that exceeds DDoS protection ...

Apr 17, 2023
CVE-2023-28982 7.5

This vulnerability allows an unauthenticated network attacker to cause a memory leak in Juniper's routing protocol daemon (rpd) during BGP rib shardin...

Apr 17, 2023
CVE-2023-28960 8.2

This CVE allows a local authenticated low-privileged attacker to copy malicious files into existing Docker containers on Juniper Junos OS Evolved syst...

Apr 17, 2023
CVE-2023-28964 7.5

This vulnerability allows an unauthenticated attacker to crash the routing protocol daemon (RPD) on Juniper devices by sending a malformed BGP flowspe...

Apr 17, 2023
CVE-2023-28966 7.8

This vulnerability allows a local attacker with shell access and low privileges to modify system files or execute commands as root due to improper fil...

Apr 17, 2023
CVE-2022-22221 7.8

This CVE describes an improper input validation vulnerability in Juniper Junos OS download manager that allows locally authenticated low-privileged us...

Jul 20, 2022
CVE-2022-22205 7.5

This CVE describes a memory leak vulnerability in Juniper SRX Series firewalls running Junos OS. An unauthenticated attacker can send specific network...

Jul 20, 2022
CVE-2022-22207 7.5

This CVE describes a use-after-free vulnerability in Juniper's AFT manager process that allows unauthenticated attackers to cause a kernel crash and d...

Jul 20, 2022
CVE-2022-22212 7.5

This CVE describes an unauthenticated resource exhaustion vulnerability in Juniper Junos OS Evolved's Packet Forwarding Engine. An attacker can send h...

Jul 20, 2022
CVE-2022-22170 7.5

This CVE describes a memory leak vulnerability in Juniper Junos OS Packet Forwarding Engine (PFE) that allows unauthenticated attackers to cause denia...

Jan 19, 2022
CVE-2022-22173 7.5

This CVE describes a memory leak vulnerability in Juniper Networks Junos OS PKI daemon (pkid) that occurs when Certificate Revocation List (CRL) downl...

Jan 19, 2022
CVE-2022-22175 7.5

An improper locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX and SRX Series devices allows unauthenticated attackers to crash t...

Jan 19, 2022
CVE-2022-22178 7.5

A stack-based buffer overflow in Juniper's flow processing daemon (flowd) allows unauthenticated attackers to cause denial of service by sending speci...

Jan 19, 2022
CVE-2022-22180 7.5

This CVE describes an improper condition check vulnerability in Juniper EX Series devices that allows specially crafted IPv6 packets to exhaust Packet...

Jan 19, 2022
CVE-2022-22152 7.7

This CVE-2022-22152 is a protection mechanism failure in Juniper Contrail Service Orchestration's REST API that allows one tenant to view another tena...

Jan 19, 2022
CVE-2022-22157 7.2

This vulnerability in Juniper SRX Series firewalls allows attackers to bypass Deep Packet Inspection rules when 'no-syn-check' is enabled, potentially...

Jan 19, 2022
CVE-2022-22161 7.5

This vulnerability allows unauthenticated attackers to cause a denial of service by flooding traffic to the out-of-band management ethernet port on Ju...

Jan 19, 2022
CVE-2022-22163 7.4

An improper input validation vulnerability in Juniper's DHCP daemon (jdhcpd) allows adjacent unauthenticated attackers to crash the service by sending...

Jan 19, 2022
CVE-2022-22167 7.2

This vulnerability in Juniper SRX Series firewalls allows attackers to bypass Deep Packet Inspection rules when 'no-syn-check' is enabled, potentially...

Jan 19, 2022
CVE-2021-31379 7.5

This CVE-2021-31379 is an incorrect behavior order vulnerability in Juniper Junos OS MAP-E automatic tunneling mechanism that allows attackers to send...

Oct 19, 2021
CVE-2021-31383 7.5

A stack-based buffer overflow vulnerability in Juniper's routing protocol daemon (RPD) allows remote unauthenticated attackers to crash the RPD servic...

Oct 19, 2021
CVE-2021-31385 8.8

This path traversal vulnerability in Juniper Networks Junos OS J-Web interface allows authenticated low-privileged users to escape directory restricti...

Oct 19, 2021
CVE-2021-31372 8.8

CVE-2021-31372 is an improper input validation vulnerability in Juniper Networks Junos OS J-Web interface that allows locally authenticated attackers ...

Oct 19, 2021
CVE-2021-31374 7.5

This vulnerability allows remote attackers to cause a denial of service on Juniper Networks devices by sending specially crafted BGP UPDATE or KEEPALI...

Oct 19, 2021
CVE-2021-31376 7.5

An improper input validation vulnerability in the Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows attackers to cau...

Oct 19, 2021
CVE-2021-31359 7.8

This CVE describes a local privilege escalation vulnerability in Juniper Junos OS and Junos OS Evolved where a low-privileged local user can crash the...

Oct 19, 2021
CVE-2021-31368 7.5

This vulnerability allows unauthenticated attackers to cause a denial of service by flooding traffic to the out-of-band management ethernet port on af...

Oct 19, 2021
CVE-2021-0299 7.5

A vulnerability in Juniper Junos OS allows remote attackers to cause a denial of service by sending specially crafted IPv6 packets. When processed, th...

Oct 19, 2021
CVE-2021-31349 9.8

This CVE describes an authentication bypass vulnerability in Juniper Networks 128 Technology Session Smart Router where an attacker can use an interna...

Oct 19, 2021
CVE-2021-31351 7.5

This vulnerability allows an attacker to cause a denial of service on Juniper MX Series routers by sending specially crafted packets that trigger a re...

Oct 19, 2021
CVE-2021-31353 7.5

This CVE describes an Improper Handling of Exceptional Conditions vulnerability in Juniper Junos OS and Junos OS Evolved. An attacker can send a speci...

Oct 19, 2021
CVE-2021-31355 8.0

This persistent cross-site scripting (XSS) vulnerability in Juniper Junos OS captive portal GUI allows authenticated remote attackers to inject malici...

Oct 19, 2021
CVE-2021-31357 7.8

This CVE describes a command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved. It allows authenticated users...

Oct 19, 2021
CVE-2021-39531 8.8

CVE-2021-39531 is a stack-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause...

Sep 20, 2021
CVE-2021-39533 8.8

CVE-2021-39533 is a heap-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause ...

Sep 20, 2021
CVE-2021-0285 7.5

This vulnerability allows attackers to cause denial of service on Juniper QFX5000 and EX4600 switches by sending large amounts of legitimate traffic t...

Jul 15, 2021
CVE-2021-0276 9.8

A stack-based buffer overflow vulnerability in Juniper Networks SBR Carrier with EAP authentication allows attackers to crash the RADIUS daemon, causi...

Jul 15, 2021
CVE-2021-0278 8.8

CVE-2021-0278 is an improper input validation vulnerability in Juniper Networks Junos OS J-Web interface that allows locally authenticated users to es...

Jul 15, 2021
CVE-2021-0280 7.5

This vulnerability in Juniper Junos OS prevents DDoS protection configuration changes from taking effect on specific PTX and QFX10K platforms with Par...

Jul 15, 2021
CVE-2021-0282 7.5

This vulnerability allows an attacker to cause a denial of service on Juniper Junos OS devices by sending a specially crafted BGP UPDATE message. The ...

Jul 15, 2021
CVE-2021-0275 8.8

This is a cross-site scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web interface that allows an attacker to hijack another user's activ...

Apr 22, 2021
CVE-2021-0244 7.4

A race condition in Juniper Junos OS Layer 2 Address Learning Daemon (L2ALD) allows attackers to bypass storm-control protections during specific admi...

Apr 22, 2021
CVE-2021-0246 7.3

This CVE allows tenant system administrators on affected Juniper SRX devices to inadvertently send their network traffic to other tenants while modify...

Apr 22, 2021
CVE-2021-0248 10.0

This vulnerability involves hard-coded credentials in Juniper Junos OS on NFX Series devices, allowing attackers to take over any NFX deployment insta...

Apr 22, 2021

Why Monitor Juniper Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 219+ known vulnerabilities affecting Juniper products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Juniper packages in under 60 seconds. No agents required - completely agentless scanning that works across Juniper deployments.

Free vulnerability database: Access detailed information about every Juniper CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Juniper CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Juniper CVEs Free