Vulnerabilities > Juniper > Junos OS Evolved

DATE CVE VULNERABILITY TITLE RISK
2022-04-14 CVE-2022-22194 Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Junos OS Evolved
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos OS Evolved on PTX10003, PTX10004, and PTX10008 allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
network
low complexity
juniper CWE-754
7.5
2022-04-14 CVE-2022-22195 Improper Update of Reference Count vulnerability in Juniper Junos OS Evolved
An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS).
network
low complexity
juniper CWE-911
7.5
2022-04-14 CVE-2022-22196 Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Junos and Junos OS Evolved
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS).
low complexity
juniper CWE-754
6.5
2022-04-14 CVE-2022-22197 Operation on a Resource after Expiration or Release vulnerability in Juniper Junos and Junos OS Evolved
An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an established BGP session to cause a Denial of Service (DoS).
network
low complexity
juniper CWE-672
7.5
2022-01-19 CVE-2022-22164 Improper Initialization vulnerability in Juniper Junos OS Evolved 20.4/21.1/21.2
An Improper Initialization vulnerability in Juniper Networks Junos OS Evolved may cause a commit operation for disabling the telnet service to not take effect as expected, resulting in the telnet service staying enabled.
network
low complexity
juniper CWE-665
5.3
2022-01-19 CVE-2022-22169 Improper Initialization vulnerability in Juniper Junos 15.1/18.3
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any Grace-LSA received in OSPFv3 causing a Denial of Service (DoS).
network
high complexity
juniper CWE-665
5.9
2022-01-19 CVE-2022-22172 Memory Leak vulnerability in Juniper Junos and Junos OS Evolved
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak.
low complexity
juniper CWE-401
6.5
2022-01-19 CVE-2022-22177 Improper Handling of Exceptional Conditions vulnerability in Juniper Junos 12.3/15.1/18.3
A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted.
network
low complexity
juniper CWE-755
7.5
2021-10-19 CVE-2021-0297 Improper Handling of Exceptional Conditions vulnerability in Juniper Junos OS Evolved 20.3/20.4/21.1
A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled.
network
low complexity
juniper CWE-755
6.5
2021-10-19 CVE-2021-0298 Race Condition vulnerability in Juniper Junos OS Evolved
A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS) condition.
local
high complexity
juniper CWE-362
4.7