Vulnerabilities > Juniper > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2021-0224 Allocation of Resources Without Limits or Throttling vulnerability in Juniper Junos
A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes in Juniper Networks Junos OS can cause the Access Node Control Protocol daemon (ANCPD) to crash and restart, leading to a Denial of Service (DoS) condition.
low complexity
juniper CWE-770
6.5
2021-04-22 CVE-2021-0216 Unspecified vulnerability in Juniper Junos
A vulnerability in Juniper Networks Junos OS running on the ACX5448 and ACX710 platforms may cause BFD sessions to flap when a high rate of transit ARP packets are received.
low complexity
juniper
6.5
2021-04-22 CVE-2021-0214 Improper Input Validation vulnerability in Juniper Junos
A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS may cause receipt of a malformed packet to crash and restart the PPMD process, leading to network destabilization, service interruption, and a Denial of Service (DoS) condition.
low complexity
juniper CWE-20
6.5
2021-01-15 CVE-2021-0221 Infinite Loop vulnerability in Juniper Junos
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic.
low complexity
juniper CWE-835
6.5
2021-01-15 CVE-2021-0220 Insufficiently Protected Credentials vulnerability in Juniper Junos Space
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI.
network
low complexity
juniper CWE-522
6.8
2021-01-15 CVE-2021-0219 OS Command Injection vulnerability in Juniper Junos
A command injection vulnerability in install package validation subsystem of Juniper Networks Junos OS that may allow a locally authenticated attacker with privileges to execute commands with root privilege.
local
low complexity
juniper CWE-78
6.7
2021-01-15 CVE-2021-0215 Memory Leak vulnerability in Juniper Junos
On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator port interface flaps which can lead to other processes, such as the pfex process, responsible for packet forwarding, to crash and restart.
low complexity
juniper CWE-401
6.5
2021-01-15 CVE-2021-0212 Insufficiently Protected Credentials vulnerability in Juniper Contrail Networking
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system.
local
low complexity
juniper CWE-522
5.0
2021-01-15 CVE-2021-0210 Information Exposure vulnerability in Juniper Junos
An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevate their privileges over the target system through opportunistic use of an authenticated users session.
network
high complexity
juniper CWE-200
6.8
2021-01-15 CVE-2021-0209 Access of Uninitialized Pointer vulnerability in Juniper Junos OS Evolved 19.4/20.1
In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to access an uninitialized pointer causing RPD to core leading to a Denial of Service (DoS).
low complexity
juniper CWE-824
6.5