Juniper
Juniper Junos OS Evolved: vulnerabilidades y CVE
Juniper Junos OS Evolved tiene 248 vulnerabilidades publicadas, 34 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE248
Últimos 12 meses34
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57029 | Media (6) | 0.19% | — | 9 jul 2026 | A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the… |
| CVE-2026-57028 | Media (6.9) | 0.30% | — | 9 jul 2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an… |
| CVE-2026-57025 | Media (6.8) | 0.14% | — | 9 jul 2026 | A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX… |
| CVE-2026-33803 | Media (6.9) | 0.35% | — | 9 jul 2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and… |
| CVE-2026-33801 | Alta (7.1) | 0.28% | — | 9 jul 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a… |
| CVE-2026-33799 | Media (5.3) | 0.37% | — | 9 jul 2026 | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory… |
| CVE-2026-33794 | Alta (8.2) | 0.40% | — | 9 jul 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker… |
| CVE-2026-21901 | Media (6.7) | 0.17% | — | 9 jul 2026 | A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration… |
| CVE-2026-33797 | Alta (7.1) | 0.27% | — | 9 abr 2026 | An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to… |
| CVE-2026-33793 | Alta (8.5) | 0.17% | — | 9 abr 2026 | An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the… |
| CVE-2026-33791 | Alta (8.4) | 0.67% | — | 9 abr 2026 | An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell… |
| CVE-2026-33788 | Alta (8.5) | 0.17% | — | 9 abr 2026 | A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain… |
| CVE-2026-33783 | Alta (7.1) | 0.42% | — | 9 abr 2026 | A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a… |
| CVE-2026-33780 | Alta (7.1) | 0.28% | — | 9 abr 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a… |
| CVE-2026-33776 | Media (6.8) | 0.13% | — | 9 abr 2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. A local user with low privileges can execute the… |
| CVE-2026-21919 | Alta (7.1) | 0.23% | — | 9 abr 2026 | An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS)… |
| CVE-2025-59969 | Alta (7.1) | 0.18% | — | 9 abr 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series… |
| CVE-2026-21902 | Crítica (9.3) | 18% | — | 25 feb 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to… |
| CVE-2026-21921 | Alta (7.1) | 0.38% | — | 15 ene 2026 | A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS).… |
| CVE-2026-21911 | Alta (7.1) | 0.24% | — | 15 ene 2026 | An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause… |
| CVE-2026-21909 | Alta (7.1) | 0.26% | — | 15 ene 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS… |
| CVE-2026-21908 | Alta (7.5) | 0.32% | — | 15 ene 2026 | A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port… |
| CVE-2025-60011 | Media (6.9) | 0.47% | — | 15 ene 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an… |
| CVE-2025-60003 | Alta (8.7) | 0.42% | — | 15 ene 2026 | A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an… |
| CVE-2025-59961 | Media (6.8) | 0.13% | — | 15 ene 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix… |
| CVE-2025-59960 | Media (6.3) | 0.26% | — | 15 ene 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address… |
| CVE-2025-59959 | Media (6.8) | 0.15% | — | 15 ene 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a… |
| CVE-2025-60010 | Media (5.3) | 0.18% | — | 9 oct 2025 | A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change.… |
| CVE-2025-60006 | Media (4.8) | 0.99% | — | 9 oct 2025 | Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges… |
| CVE-2025-60004 | Alta (8.7) | 0.42% | — | 9 oct 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a… |