Vulnerabilities > Juniper > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-15 CVE-2021-0207 Interpretation Conflict vulnerability in Juniper Junos 17.3/17.4/18.1
An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering certain specific types of traffic which is then being redirected to an egress interface on a different VLAN.
network
low complexity
juniper CWE-436
5.0
2021-01-15 CVE-2021-0206 NULL Pointer Dereference vulnerability in Juniper Junos
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS).
network
low complexity
juniper CWE-476
5.0
2021-01-15 CVE-2021-0205 Unspecified vulnerability in Juniper Junos 17.3/17.4/18.1
When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to block unexpected traffic.
network
juniper
4.3
2021-01-15 CVE-2021-0203 Unspecified vulnerability in Juniper Junos 15.1/16.1
On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition.
network
juniper
4.3
2021-01-15 CVE-2021-0202 Memory Leak vulnerability in Juniper Junos
On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Customer Edge (CE) device may cause memory leak in the MPC which can cause an out of memory and MPC restarts.
network
low complexity
juniper CWE-401
5.0
2020-10-16 CVE-2020-1685 Information Exposure Through Discrepancy vulnerability in Juniper Junos
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions.
network
low complexity
juniper CWE-203
5.0
2020-10-16 CVE-2020-1684 Unspecified vulnerability in Juniper Junos
On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lead to traffic interruption.
network
juniper
4.3
2020-10-16 CVE-2020-1681 Reachable Assertion vulnerability in Juniper Junos OS Evolved
Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS).
low complexity
juniper CWE-617
6.5
2020-10-16 CVE-2020-1680 Incorrect Calculation of Buffer Size vulnerability in Juniper Junos 15.1/15.1X53/18.2
On Juniper Networks MX Series with MS-MIC or MS-MPC card configured with NAT64 configuration, receipt of a malformed IPv6 packet may crash the MS-PIC component on MS-MIC or MS-MPC.
network
low complexity
juniper CWE-131
5.0
2020-10-16 CVE-2020-1679 Unspecified vulnerability in Juniper Junos
On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck.
network
juniper
4.3