Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.64% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash,… | |
| Modificada | Alta (7.5) | 0.63% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition. Service… | |
| Modificada | Alta (7.5) | 0.65% | — | Juniper JunosJuniper Junos OS Evolved | 21/6/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a BGP update message is received over an established BGP session, and that message contains a… | |
| Modificada | Media (5.3) | 0.21% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of MAC learning and aging happens, but due… | |
| Modificada | Alta (8.8) | 1.5% | — | Juniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects Juniper Networks Junos OS Evolved 21.4 version 21.4R1-EVO… | |
| Modificada | Alta (7.5) | 0.65% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scenario, when an attribute of an active BGP route is updated… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If the receipt of router advertisements is enabled on an interface and a specifically malformed RA packet is received, memory… | |
| Modificada | Media (5.5) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause Denial of Service (DoS). In a rib sharding scenario the rpd process will crash shortly after specific CLI command is issued. This issue is… | |
| Modificada | Media (4.7) | 0.27% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity check. In a 6PE scenario and if an additional integrity check is configured, it will fail to drop specific malformed IPv6 packets, and then… | |
| Modificada | Media (5.3) | 0.47% | — | Juniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to read confidential information about locally configured (administrative) users of… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If specific traffic is received on MX Series and its rate exceeds the respective… | |
| Modificada | Media (4.6) | 0.29% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a Denial of Service (DoS). When certain USB devices are connected to a USB port of the routing-engine (RE), the kernel will crash leading to… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to… | |
| Modificada | Alta (7.1) | 0.15% | — | Juniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions such as daemon restarting, routing… | |
| Modificada | Media (6.8) | 0.37% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be… | |
| Modificada | Alta (7.2) | 0.39% | — | Juniper Paragon Active Assurance | 17/4/2023 | 17/6/2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to restrict internal communcations. The Test Agents (TA)… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the device to cause a kernel crash, resulting in a Denial of… | |
| Modificada | Media (5.3) | 0.57% | — | Juniper Appid Service SigpackJuniper Jdpi-decoder EngineJuniper Junos | 17/4/2023 | 17/6/2026 | — | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos OS EvolvedJuniper Junos | 17/4/2023 | 17/6/2026 | A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial of Service (DoS) by crashing the Routing… | |
| Modificada | Alta (7.8) | 0.16% | — | Juniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system files, allowing an attacker with access to… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. Storm… | |
| Modificada | Alta (7.5) | 0.65% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | — | |
| Modificada | Media (5.3) | 0.49% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.1R3-S10; 19.2… | |
| Modificada | Crítica (9.8) | 0.56% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.4R3-S11; 20.1… | |
| Modificada | Media (5.3) | 0.42% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Handling of Unexpected Data Type vulnerability in IPv6 firewall filter processing of Juniper Networks Junos OS on the ACX Series devices will prevent a firewall filter with the term 'from next-header ah' from being properly installed in the packet forwarding engine (PFE). There is no immediate indication… |