Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Juniper Junos OS Evolved | 14/4/2022 | 17/6/2026 | An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to… | |
| Modificada | Alta (7.5) | 0.96% | — | Juniper JunosJuniper Junos OS Evolved | 19/1/2022 | 17/6/2026 | A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impacts any version of SNMP – v1,v2, v3 This issue affects:… | |
| Modificada | Media (6.5) | 0.37% | — | Juniper JunosJuniper Junos OS Evolved | 19/1/2022 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service… | |
| Modificada | Media (5.9) | 0.83% | — | Juniper JunosJuniper Junos OS Evolved | 19/1/2022 | 17/6/2026 | An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any… | |
| Modificada | Media (5.3) | 0.70% | — | Juniper Junos OS Evolved | 19/1/2022 | 17/6/2026 | An Improper Initialization vulnerability in Juniper Networks Junos OS Evolved may cause a commit operation for disabling the telnet service to not take effect as expected, resulting in the telnet service staying enabled. When it is not intended to be operating on the device, an administrator can issue the following… | |
| Modificada | Alta (7.5) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the routing protocol daemon (RPD) of Juniper Networks Junos OS… | |
| Modificada | Alta (7.5) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this message will create a sustained Denial of Service (DoS)… | |
| Modificada | Media (6.5) | 0.40% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause high load on RPD which in turn may lead to routing protocol flaps. If a system with… | |
| Modificada | Media (6.5) | 0.42% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading to a Denial of Service (DoS) condition. Continued… | |
| Modificada | Alta (7.1) | 0.21% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending on the files overwritten, exploitation of… | |
| Modificada | Alta (7.8) | 0.24% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. Continued processing of malicious input will… | |
| Modificada | Alta (7.8) | 0.62% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to… | |
| Modificada | Alta (7.8) | 0.63% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to… | |
| Modificada | Alta (7.8) | 0.87% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass… | |
| Modificada | Alta (8.8) | 0.63% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause a partial Denial of Service (DoS), or lead to remote code… | |
| Modificada | Alta (7.5) | 1.2% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued receipt and processing of the BGP update… | |
| Modificada | Alta (8.8) | 0.87% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to complete compromise of the targeted system.… | |
| Modificada | Media (4.7) | 0.17% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS)… | |
| Modificada | Media (6.5) | 0.73% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to untrusted or unauthorized sessions being established,… | |
| Modificada | Media (6.5) | 0.38% | — | Juniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS Evolved allows a malicious attacker on the local network to consume memory resources, ultimately resulting in a Denial of Service (DoS) condition. Link-layer functions… | |
| Modificada | Media (6.5) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traffic which partially reaches this resource. A high rate of specific traffic may… | |
| Modificada | Media (6.5) | 0.37% | — | Juniper JunosJuniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routing process daemon (RPD) crash and restart, causing a Denial… | |
| Modificada | Alta (7.5) | 1.1% | — | Juniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) allows an attacker to send specially crafted packets to the device, causing the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) process to crash and restart, impacting all traffic going through… | |
| Modificada | Media (5.3) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960 devices with affected Trio line cards allows an attacker to exploit an interdependency in the PFE UCODE microcode of the Trio… | |
| Modificada | Alta (7.5) | 0.98% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card to crash and restart, creating a Denial of Service (DoS). Continued receipt and… |