Vulnerabilities > Juniper > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-01-15 CVE-2019-0007 Use of Insufficiently Random Values vulnerability in Juniper Junos 15.1
The vMX Series software uses a predictable IP ID Sequence Number.
network
low complexity
juniper CWE-330
critical
10.0
2019-01-15 CVE-2019-0006 Use of Uninitialized Resource vulnerability in Juniper Junos 14.1X53/15.1/15.1X53
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration.
network
low complexity
juniper CWE-908
critical
9.8
2019-01-15 CVE-2019-0002 Unspecified vulnerability in Juniper Junos 15.1X53/18.1/18.2
On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take effect.
network
low complexity
juniper
critical
9.8
2018-10-10 CVE-2018-0057 Unspecified vulnerability in Juniper Junos
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address binding in the access profile.
network
low complexity
juniper
critical
9.6
2018-07-11 CVE-2018-0042 Information Exposure Through Log Files vulnerability in Juniper Contrail Service Orchestration
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
network
low complexity
juniper CWE-532
critical
9.8
2018-07-11 CVE-2018-0041 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0040 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0039 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0038 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0037 Improper Input Validation vulnerability in Juniper Junos 15.1
Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages.
network
low complexity
juniper CWE-20
critical
9.8