Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Juniper

Vulnerabilities in Juniper Networks Junos OS, SRX Series firewalls, and other carrier- and enterprise-grade network hardware — the routing and firewall gear that sits at the edge of large networks, where a bug on the management plane often means full device compromise.

8 CVEs0 articlesRSS
CVEs
CVE-2015-7755
[ CRITICAL ]CVSS 9.8EPSS 61.4%kev

Juniper ScreenOS Improper Authentication Vulnerability

Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.

Juniper / ScreenOS
CVE-2025-21590
[ MEDIUM ]CVSS 4.4EPSS 1.7%kev

Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

Juniper / Junos OS
CVE-2023-36844
[ MEDIUM ]CVSS 5.3EPSS 91.0%kev

Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.

Juniper / Junos OS
CVE-2023-36845
[ CRITICAL ]CVSS 9.8EPSS 94.6%kev

Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

Juniper / Junos OS
CVE-2023-36846
[ MEDIUM ]CVSS 5.3EPSS 95.1%kev

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

Juniper / Junos OS
CVE-2023-36847
[ MEDIUM ]CVSS 5.3EPSS 85.8%kev

Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

Juniper / Junos OS
CVE-2023-36851
[ MEDIUM ]CVSS 5.3EPSS 1.1%kev

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

Juniper / Junos OS
CVE-2020-1631
[ HIGH ]CVSS 8.8EPSS 4.7%kev

Juniper Junos OS Path Traversal Vulnerability

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

Juniper / Junos OS