Juniper Junos OS
Our sources currently list 788 known vulnerabilities affecting Juniper Junos OS. 32 are rated critical severity. 7 of 788 are actively exploited according to CISA, the most recent added 13 March 2025.
Last updated: 22 July 2026, 20:42 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2023-36846 | Medium (5.3) | Actively exploited | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to… | |
| CVE-2023-36845 | Critical (9.8) | Actively exploited | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remote… | |
| CVE-2023-36844 | Medium (5.3) | Actively exploited | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, importan… | |
| CVE-2023-36847 | Medium (5.3) | Actively exploited | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to … | |
| CVE-2020-1631 | High (8.8) | Actively exploited | A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning… | |
| CVE-2025-21590 | Medium (4.4) | Actively exploited | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of t… | |
| CVE-2023-36851 | Medium (5.3) | Actively exploited | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to… | |
| CVE-2019-11358 | Medium (6.1) | Elevated likelihood (87%) | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob… | |
| CVE-2004-0230 | Medium (5.0) | Elevated likelihood (80%) | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by… | |
| CVE-2020-10188 | Critical (9.8) | Elevated likelihood (75%) | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the net… | |
| CVE-2016-1286 | High (8.6) | Elevated likelihood (62%) | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature r… | |
| CVE-2016-1285 | Medium (6.8) | Elevated likelihood (59%) | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a… | |
| CVE-2014-9708 | Medium (5.0) | Elevated likelihood (56%) | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demons… | |
| CVE-2017-3145 | High (7.5) | Elevated likelihood (28%) | BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and cr… | |
| CVE-2016-7103 | Medium (6.1) | Elevated likelihood (23%) | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog fu… | |
| CVE-2024-21591 | Critical (9.8) | Elevated likelihood (18%) | An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Servi… | |
| CVE-2023-4481 | High (7.5) | Elevated likelihood (15%) | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker … | |
| CVE-2013-6618 | Critical (9.0) | Elevated likelihood (11%) | jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to… | |
| CVE-2013-4685 | Critical (10.0) | No exploitation reported | Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled… | |
| CVE-2018-0001 | Critical (9.8) | No exploitation reported | A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific P… | |
| CVE-2020-7656 | Medium (6.1) | No exploitation reported | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace characte… | |
| CVE-2019-0006 | Critical (9.8) | No exploitation reported | A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devi… | |
| CVE-2018-0052 | High (7.2) | No exploitation reported | If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by … | |
| CVE-2019-0008 | Critical (9.8) | No exploitation reported | A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4… | |
| CVE-2006-3529 | Medium (5.0) | No exploitation reported | Memory leak in Juniper JUNOS 6.4 through 8.0, built before May 10, 2006, allows remote attackers to cause a denial of service (kernel packet memory consumption and crash) via craft… | |
| CVE-2018-0016 | Critical (9.8) | No exploitation reported | Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code exe… | |
| CVE-2004-0467 | Medium (5.0) | No exploitation reported | Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified b… | |
| CVE-2013-6013 | Medium (6.8) | No exploitation reported | Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 12.1X45-D10 on SRX devices, when… | |
| CVE-2015-5362 | Critical (9.3) | No exploitation reported | The BFD daemon in Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before … | |
| CVE-2018-0037 | Critical (9.8) | No exploitation reported | Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. By continuously sendi… | |
| CVE-2007-6372 | High (7.8) | No exploitation reported | Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that … | |
| CVE-2017-2345 | Critical (9.8) | No exploitation reported | On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and restart by sending a crafted SNMP … | |
| CVE-2014-0618 | High (7.8) | No exploitation reported | Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when u… | |
| CVE-2014-3817 | High (7.8) | No exploitation reported | Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NA… | |
| CVE-2021-25220 | Medium (6.8) | No exploitation reported | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those sho… | |
| CVE-2004-0468 | Medium (5.0) | No exploitation reported | Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets. | |
| CVE-2019-0001 | High (7.5) | No exploitation reported | Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bb… | |
| CVE-2014-6380 | High (7.8) | No exploitation reported | Juniper Junos 11.4 before R11, 12.1 before R9, 12.1X44 before D30, 12.1X45 before D20, 12.1X46 before D15, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 1… | |
| CVE-2016-4921 | High (7.5) | No exploitation reported | By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop info… | |
| CVE-2018-0048 | High (7.5) | No exploitation reported | A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhau… | |
| CVE-2016-1279 | Critical (9.8) | No exploitation reported | J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1… | |
| CVE-2015-7748 | Medium (5.0) | No exploitation reported | Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R2 allow remote attackers to cau… | |
| CVE-2018-15504 | High (7.5) | No exploitation reported | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL poin… | |
| CVE-2013-4684 | High (7.8) | No exploitation reported | flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R8, 12.1 before 12.1R7, and 12.1X44 before 12.1X44-D15 on SRX devices, when PIM and NAT are enabled, allows remote attac… | |
| CVE-2019-0010 | High (7.5) | No exploitation reported | An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer ex… | |
| CVE-2014-3819 | High (7.8) | No exploitation reported | Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before … | |
| CVE-2014-6386 | High (7.8) | No exploitation reported | Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before … | |
| CVE-2017-2343 | Critical (10.0) | No exploitation reported | The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide simple integration of user profiles on top… | |
| CVE-2020-1647 | Critical (9.8) | No exploitation reported | On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remot… | |
| CVE-2015-5358 | High (7.1) | No exploitation reported | Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 bef… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
7 of these are being actively exploited right now.
Our Newcastle team can audit your Juniper estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
