Summary
Detail | |||
---|---|---|---|
Vendor | Juniper | First view | 2015-01-16 |
Product | Junos | Last view | 2024-01-25 |
Version | 12.3 | Type | Os |
Update | r1 | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:o:juniper:junos |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.1 | 2024-01-25 | CVE-2024-21620 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. A specific invocation of the emit_debug_note method in webauth_operation.php will echo back the data it receives. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: |
7.5 | 2024-01-25 | CVE-2024-21619 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: |
5.3 | 2024-01-12 | CVE-2024-21607 | An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause partial impact to the integrity of the device. If the "tcp-reset" option is added to the "reject" action in an IPv6 filter which matches on "payload-protocol", packets are permitted instead of rejected. This happens because the payload-protocol match criteria is not supported in the kernel filter causing it to accept all packets without taking any other action. As a fix the payload-protocol match will be treated the same as a "next-header" match to avoid this filter bypass. This issue doesn't affect IPv4 firewall filters. This issue affects Juniper Networks Junos OS on MX Series and EX9200 Series: * All versions earlier than 20.4R3-S7; |
7.5 | 2024-01-12 | CVE-2024-21606 | A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is configured and a sequence of specific packets is received, a flowd crash and restart will be observed. This issue affects Juniper Networks Junos OS on SRX Series: * All versions earlier than 20.4R3-S8; |
5.5 | 2024-01-12 | CVE-2024-21594 | A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). On an SRX 5000 Series device, when executing a specific command repeatedly, memory is corrupted, which leads to a Flow Processing Daemon (flowd) crash. The NSD process has to be restarted to restore services. If this issue occurs, it can be checked with the following command: user@host> request security policies check The following log message can also be observed: Error: policies are out of sync for PFE node Juniper Networks Junos OS on SRX 5000 Series * All versions earlier than 20.4R3-S6; |
9.8 | 2024-01-12 | CVE-2024-21591 | An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory. This issue affects Juniper Networks Junos OS SRX Series and EX Series: * Junos OS versions earlier than 20.4R3-S9; |
6.5 | 2024-01-12 | CVE-2023-36842 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). On Junos OS devices with forward-snooped-client configured, if an attacker sends a specific DHCP packet to a non-configured interface, this will cause an infinite loop. The DHCP process will have to be restarted to recover the service. This issue affects: Juniper Networks Junos OS * All versions earlier than 20.4R3-S9; |
6.5 | 2023-10-13 | CVE-2023-44203 | An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600 allows a adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). When a specific IGMP packet is received in an isolated VLAN, it is duplicated to all other ports under the primary VLAN, which causes a flood. This issue affects QFX5000 series, EX2300, EX3400, EX4100, EX4400 and EX4600 platforms only. This issue affects Juniper Junos OS on on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: * All versions prior to 20.4R3-S5; |
5.5 | 2023-10-13 | CVE-2023-44201 | An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions. When a user with the respective permissions commits a configuration change, a specific file is created. That file is readable even by users with no permissions to access the configuration. This can lead to privilege escalation as the user can read the password hash when a password change is being committed. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S4; Juniper Networks Junos OS Evolved * All versions prior to 20.4R3-S4-EVO; |
7.5 | 2023-10-13 | CVE-2023-44199 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart. This issue affects Juniper Networks Junos OS on MX Series: * All versions prior to 20.4R3-S4; |
7.5 | 2023-10-13 | CVE-2023-44198 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks. If the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: * 20.4 versions prior to 20.4R3-S5; This issue doesn't not affected releases prior to 20.4R1. |
7.5 | 2023-10-13 | CVE-2023-44197 | An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and restart can occur while processing BGP route updates received over an established BGP session. This specific issue is observed for BGP routes learned via a peer which is configured with a BGP import policy that has hundreds of terms matching IPv4 and/or IPv6 prefixes. This issue affects Juniper Networks Junos OS: * All versions prior to 20.4R3-S8; This issue affects Juniper Networks Junos OS Evolved: * All versions prior to 20.4R3-S8-EVO; |
7.8 | 2023-10-13 | CVE-2023-44194 | An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. The issue is caused by improper directory permissions on a certain system directory, allowing an attacker with access to this directory to create a backdoor with root privileges. This issue affects Juniper Networks Junos OS: * All versions prior to 20.4R3-S5; |
5.5 | 2023-10-13 | CVE-2023-44193 | An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). On all Junos MX Series with MPC1 - MPC9, LC480, LC2101, MX10003, and MX80, when Connectivity-Fault-Management (CFM) is enabled in a VPLS scenario, and a specific LDP related command is run, an FPC will crash and reboot. Continued execution of this specific LDP command can lead to sustained Denial of Service condition. This issue affects: Juniper Networks Junos OS on MX Series: * All versions prior to 20.4R3-S7; |
7.5 | 2023-10-13 | CVE-2023-44192 | An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak. To confirm the memory leak, monitor for "sheaf:possible leak" and "vtep not found" messages in the logs. This issue affects: Juniper Networks Junos OS QFX5000 Series: * All versions prior to 20.4R3-S6; |
7.5 | 2023-10-13 | CVE-2023-44185 | An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (DoS )to the device upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet. Continued receipt of this packet will cause a sustained Denial of Service condition. This issue affects: * Juniper Networks Junos OS: Juniper Networks Junos OS Evolved: * All versions prior to 20.4R3-S6-EVO; |
6.5 | 2023-10-13 | CVE-2023-44184 | An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a specific command via NETCONF, to cause a CPU Denial of Service to the device's control plane. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S7; Juniper Networks Junos OS Evolved * All versions prior to 21.4R3-S4-EVO; An indicator of compromise can be seen by first determining if the NETCONF client is logged in and fails to log out after a reasonable period of time and secondly reviewing the WCPU percentage for the mgd process by running the following command: mgd process example: user@device-re#> show system processes extensive | match "mgd|PID" | except last PID USERNAME PRI NICE SIZE RES STATE C TIME WCPU COMMAND 92476 root 100 0 500M 89024K CPU3 3 57.5H 89.60% mgd <<<<<<<<<<< review the high cpu percentage. Example to check for NETCONF activity: While there is no specific command that shows a specific session in use for NETCONF, you can review logs for UI_LOG_EVENT with "client-mode 'netconf'" For example: mgd[38121]: UI_LOGIN_EVENT: User 'root' login, class 'super-user' [38121], ssh-connection '10.1.1.1 201 55480 10.1.1.2 22', client-mode 'netconf' |
8.8 | 2023-10-13 | CVE-2023-44182 | An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes unintended effects such as demotion or elevation of privileges associated with an operators actions to occur. Multiple scenarios may occur; for example: privilege escalation over the device or another account, access to files that should not otherwise be accessible, files not being accessible where they should be accessible, code expected to run as non-root may run as root, and so forth. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S7; Juniper Networks Junos OS Evolved * All versions prior to 21.4R3-S3-EVO; |
7.5 | 2023-10-13 | CVE-2023-44181 | An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to ARP queue causing a l2 loop resulting in a DDOS violations and DDOS syslog. This issue is triggered when Storm control is enabled and ICMPv6 packets are present on device. This issue affects Juniper Networks: Junos OS * All versions prior to 20.2R3-S6 on QFX5k; |
5.5 | 2023-10-13 | CVE-2023-44178 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS * All versions prior to 19.1R3-S10; |
5.5 | 2023-10-13 | CVE-2023-44177 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS: * All versions prior to 19.1R3-S10; Junos OS Evolved: * All versions prior to 20.4R3-S8-EVO; |
5.5 | 2023-10-13 | CVE-2023-44176 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks: Junos OS: * All versions prior to 20.4R3-S8; |
7.5 | 2023-10-12 | CVE-2023-44175 | A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Note: This issue is not noticed when all the devices in the network are Juniper devices. This issue affects Juniper Networks: Junos OS: * All versions prior to 20.4R3-S7; Junos OS Evolved: * All versions prior to 22.3R3-EVO; |
7.5 | 2023-10-12 | CVE-2023-36843 | An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS). Upon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device. This issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via ‘security-metadata-streaming policy’). This issue affects Juniper Networks Junos OS: * All versions prior to 20.4R3-S8, 20.4R3-S9; |
7.5 | 2023-10-12 | CVE-2023-36841 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover. This issue affects interfaces with PPPoE configured and tcp-mss enabled. This issue affects Juniper Networks Junos OS * All versions prior to 20.4R3-S7; |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
11% (18) | CWE-20 | Improper Input Validation |
7% (12) | CWE-754 | Improper Check for Unusual or Exceptional Conditions |
6% (10) | CWE-787 | Out-of-bounds Write |
5% (9) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
5% (9) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
4% (8) | CWE-755 | Improper Handling of Exceptional Conditions |
4% (8) | CWE-401 | Failure to Release Memory Before Removing Last Reference ('Memory L... |
4% (8) | CWE-399 | Resource Management Errors |
3% (5) | CWE-287 | Improper Authentication |
2% (4) | CWE-770 | Allocation of Resources Without Limits or Throttling |
2% (4) | CWE-306 | Missing Authentication for Critical Function |
2% (4) | CWE-264 | Permissions, Privileges, and Access Controls |
2% (4) | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflo... |
2% (4) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
1% (3) | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition |
1% (3) | CWE-362 | Race Condition |
1% (3) | CWE-200 | Information Exposure |
1% (3) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
1% (2) | CWE-798 | Use of Hard-coded Credentials |
1% (2) | CWE-772 | Missing Release of Resource after Effective Lifetime |
1% (2) | CWE-617 | Reachable Assertion |
1% (2) | CWE-473 | PHP External Variable Modification |
1% (2) | CWE-415 | Double Free |
1% (2) | CWE-209 | Information Exposure Through an Error Message |
1% (2) | CWE-125 | Out-of-bounds Read |
SAINT Exploits
Description | Link |
---|---|
netkit telnetd nextitem vulnerability | More info here |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-A-0148 | Multiple Vulnerabilities in Juniper JUNOS OS Severity: Category I - VMSKEY: V0061071 |
Snort® IPS/IDS
Date | Description |
---|---|
2020-07-29 | netkit-telnet server memory corruption attempt RuleID : 54389 - Type : PROTOCOL-TELNET - Revision : 1 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2019-01-11 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10912.nasl - Type: ACT_GATHER_INFO |
2018-07-20 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10857.nasl - Type: ACT_GATHER_INFO |
2018-04-20 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10847.nasl - Type: ACT_GATHER_INFO |
2018-04-20 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10845.nasl - Type: ACT_GATHER_INFO |
2018-01-26 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10832.nasl - Type: ACT_GATHER_INFO |
2018-01-26 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10831.nasl - Type: ACT_GATHER_INFO |
2018-01-26 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10830.nasl - Type: ACT_GATHER_INFO |
2018-01-26 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10828.nasl - Type: ACT_GATHER_INFO |
2017-08-23 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10779.nasl - Type: ACT_GATHER_INFO |
2017-07-31 | Name: The remote device is affected by an authentication bypass vulnerability. File: juniper_jsa10802.nasl - Type: ACT_GATHER_INFO |
2017-04-20 | Name: The remote device is affected by a denial of service vulnerability. File: juniper_jsa10781.nasl - Type: ACT_GATHER_INFO |
2017-01-20 | Name: The remote device is affected by a denial of service vulnerability. File: juniper_jsa10772.nasl - Type: ACT_GATHER_INFO |
2017-01-20 | Name: The remote device is affected by a denial of service vulnerability. File: juniper_jsa10771.nasl - Type: ACT_GATHER_INFO |
2017-01-20 | Name: The remote device is affected by a denial of service vulnerability. File: juniper_jsa10769.nasl - Type: ACT_GATHER_INFO |
2016-10-27 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10764.nasl - Type: ACT_GATHER_INFO |
2016-10-27 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10763.nasl - Type: ACT_GATHER_INFO |
2016-10-27 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10762.nasl - Type: ACT_GATHER_INFO |
2016-07-22 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10755.nasl - Type: ACT_GATHER_INFO |
2016-07-22 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10754.nasl - Type: ACT_GATHER_INFO |
2016-07-22 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10750.nasl - Type: ACT_GATHER_INFO |
2016-04-27 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10723.nasl - Type: ACT_GATHER_INFO |
2016-01-22 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10720.nasl - Type: ACT_GATHER_INFO |
2016-01-22 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10714.nasl - Type: ACT_GATHER_INFO |
2015-10-26 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10707.nasl - Type: ACT_GATHER_INFO |
2015-10-21 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10696.nasl - Type: ACT_GATHER_INFO |