Known vulnerabilities in Junos OS 18.3R2-S2

Software: Junos OS
Version: 18.3R2-S2
Software CPE: cpe:2.3:o:juniper_networks:juniper_junos_os:*:*:*:*:*:*:*:*
Total vulnerabilities: 72
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Junos OS version 18.3R2-S2 Junos OS 18.3R2-S2 is affected by 72 vulnerabilities: 4 high, 43 medium, 25 low Critical High Medium Low

Vulnerabilities (72)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82509 - Improper input validation
CVE-2022-22214
CWE-20 Medium
No
No
12.3R12-S21, 15.1R7-S10, 17.3R3-S12, 18.3R3-S6, 18.4R2-S9, 18.4R3-S9, 19.1R2-S3, 19.1R3-S7, 19.2R1-S7, 19.2R3-S3, 19.3R2-S7, 19.3R3-S4, 19.4R3-S5, 20.1R3, 20.2R3-S2, 20.3R3, 20.4R2-S2, 20.4R3, 21.1R2, 21.2R1 26.10.2023 SB2022071367
#VU82464 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-22181
CWE-79 Low
No
No
18.3R3-S5, 18.4R3-S9, 19.1R3-S6, 19.2R3-S3, 19.3R2-S6, 19.3R3-S3, 19.4R3-S5, 20.1R3-S4, 20.2R3-S2, 20.3R3, 20.4R3, 21.1R1-S1, 21.1R2, 21.2R1 26.10.2023 SB2022041361
#VU75121 - Improper Handling of Length Parameter Inconsistency
CVE-2023-28964
CWE-130 Medium
No
No
18.1R3-S11, 18.2R3-S6, 18.3R3-S4, 18.4R3-S6, 19.1R3-S4, 19.2R3-S1, 19.3R3-S1, 19.4R3, 20.1R2, 20.2R2, 20.3R1-S1, 20.3R2, 20.4R1 14.04.2023 SB2023041441
#VU68578 - Missing release of memory after effective lifetime
CVE-2022-22226
CWE-401 Medium
No
No
17.3R3-S12, 17.4R2-S13, 17.4R3-S5, 18.1R3-S13, 18.2R3-S8, 18.3R3-S5, 18.4R1-S8, 18.4R2-S6, 18.4R3-S6, 19.1R3-S4, 19.2R1-S7, 19.2R3-S1, 19.3R2-S6, 19.3R3-S1, 19.4R1-S4, 19.4R2-S4, 19.4R3-S1, 20.1R2, 20.2R2-S3, 20.2R3, 20.3R2, 20.4R1 21.10.2022 SB2022102129
#VU82446 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-22182
CWE-79 Low
No
No
12.3R12-S19, 15.1R7-S10, 18.3R3-S5, 18.4R2-S10, 18.4R3-S9, 19.1R2-S3, 19.1R3-S6, 19.2R1-S8, 19.2R3-S3, 19.3R2-S6, 19.3R3-S3, 19.4R3-S5, 20.1R3-S2, 20.2R3-S2, 20.3R3, 20.4R2-S2, 20.4R3, 21.1R1-S1, 21.1R2, 21.2R1-S1, 21.2R2, 21.3R1 13.04.2022 SB2022041357
#VU82463 - Improper Check for Unusual or Exceptional Conditions
CVE-2022-22185
CWE-754 Medium
No
No
18.3R3-S6, 18.4R3-S10, 19.1R3-S7, 19.2R3-S4, 19.3R3-S4, 19.4R3-S6, 20.1R3-S2, 20.2R3-S3, 20.3R3-S1, 20.4R3, 21.1R2-S1, 21.1R3, 21.2R2, 21.3R1 13.04.2022 SB2022041360
#VU82467 - Operation on a Resource after Expiration or Release
CVE-2022-22197
CWE-672 Medium
No
No
17.3R3-S11, 17.4R2-S13, 17.4R3-S4, 18.3R3-S4, 18.4R1-S8, 18.4R2-S8, 18.4R3-S6, 19.1R3-S4, 19.2R1-S6, 19.2R3-S2, 19.3R2-S6, 19.3R3-S1, 19.4R1-S4, 19.4R2-S4, 19.4R3, 20.1R2, 20.2R2, 20.3R1-S2, 20.3R2, 20.4R1 13.04.2022 SB2022041364
#VU59635 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-31385
CWE-22 Medium
No
No
12.3R12-S19, 15.1R7-S10, 18.3R3-S5, 18.4R3-S9, 19.1R3-S6, 19.2R1-S7, 19.2R3-S3, 19.3R3-S3, 19.4R3-S5, 20.1R2-S2, 20.1R3-S1, 20.2R3-S2, 20.3R3, 20.4R2-S1, 20.4R3, 21.1R1-S1, 21.1R2, 21.2R1 17.01.2022 SB2022011707
#VU59634 - Release of invalid pointer or reference
CVE-2022-22177
CWE-763 Medium
No
No
12.3R12-S20, 15.1R7-S11, 18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R2-S5, 19.4R3-S6, 20.1R3-S2, 20.2R3-S3, 20.3R3-S1, 20.4R3, 21.1R2-S2, 21.1R3, 21.2R1-S2, 21.2R2, 21.3R1 17.01.2022 SB2022011706
#VU59632 - Inefficient Algorithmic Complexity
CVE-2022-22153
CWE-407 Medium
No
No
18.2R3, 18.3R3, 18.4R2-S9, 18.4R3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1 17.01.2022 SB2022011705
#VU59595 - Resource exhaustion
CVE-2022-22159
CWE-400 Medium
No
No
17.3R3-S12, 17.4R3-S5, 18.1R3-S13, 18.3R3-S5, 18.4R3-S9, 19.1R3-S7 13.01.2022 SB2022011322
#VU59588 - Resource exhaustion
CVE-2022-22161
CWE-400 Medium
No
No
18.3R3-S6, 18.4R2-S9, 18.4R3-S9, 19.1R2-S3, 19.1R3-S7, 19.2R1-S7, 19.2R3-S3, 19.3R2-S7, 19.3R3-S4, 19.4R2-S5, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R2-S2, 20.4R3, 21.1R2, 21.2R1-S1, 21.2R2, 21.3R1 13.01.2022 SB2022011315
#VU59587 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22162
CWE-200 Low
No
No
15.1R7-S11, 18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R3-S6, 20.1R3-S2, 20.2R3-S3, 20.3R3-S1, 20.4R3-S1, 21.1R2-S1, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1 13.01.2022 SB2022011314
#VU59567 - Improper Initialization
CVE-2022-22169
CWE-665 Medium
No
No
15.1R7-S11, 18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S7, 19.2R3-S4, 19.3R2-S7, 19.3R3-S4, 19.4R3-S6, 20.1R3-S1, 20.2R3-S3, 20.3R3-S1, 20.4R2-S2, 20.4R3, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1 12.01.2022 SB2022011232
#VU59563 - Missing release of memory after effective lifetime
CVE-2022-22173
CWE-401 Medium
No
No
18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R2-S5, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R3, 21.1R2, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1 12.01.2022 SB2022011229
#VU59561 - Missing release of memory after effective lifetime
CVE-2022-22174
CWE-401 Medium
No
No
18.3R3-S6, 18.4R2-S9, 18.4R3-S9, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S3, 19.3R2-S7, 19.3R3-S4, 19.4R2-S5, 19.4R3-S6, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R3, 21.1R2-S1, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1, 21.4R1 12.01.2022 SB2022011227
#VU57440 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-31355
CWE-79 Low
No
No
12.3X48-D105, 15.1X49-D220, 18.3R3-S5, 18.4R3-S9, 19.1R3-S7, 19.2R3-S3, 19.3R3-S4, 19.4R3-S6, 20.1R3, 20.2R1-S1, 20.2R2, 20.3R2, 20.4R2, 21.1R2, 21.2R1 19.10.2021 SB2021101918
#VU57439 - Improper Check for Unusual or Exceptional Conditions
CVE-2021-31361
CWE-754 Medium
No
No
17.3R3-S11, 17.4R2-S13, 17.4R3-S4, 18.1R3-S12, 18.2R2-S8, 18.2R3-S7, 18.3R3-S4, 18.4R1-S8, 18.4R2-S7, 18.4R3-S7, 18.4R3-S9, 19.1R1-S6, 19.1R2-S2, 19.1R3-S4, 19.1R3-S6, 19.2R1-S6, 19.2R1-S7, 19.2R3-S2, 19.2R3-S3, 19.3R2-S6, 19.3R3-S1, 19.3R3-S3, 19.4R1-S4, 19.4R2-S3, 19.4R3-S1, 19.4R3-S5, 20.1R2, 20.1R2-S2, 20.1R3, 20.2R2, 20.2R3, 20.2R3-S1, 20.3R1-S1, 20.3R2, 20.3R2-S1, 20.3R3, 20.4R1, 20.4R2-S1, 20.4R3, 21.1R1-S1, 21.1R2, 21.2R1 19.10.2021 SB2021101917
#VU57438 - Protection Mechanism Failure
CVE-2021-31362
CWE-693 Low
No
No
18.2R3-S8, 18.3R3-S5, 18.4R3-S9, 19.1R3-S7, 19.2R1-S7, 19.2R3-S3, 19.3R2-S6, 19.3R3-S2, 19.4R3-S3, 20.1R3, 20.2R3, 20.3R3, 20.4R2, 21.1R1 19.10.2021 SB2021101916
#VU57419 - Improper Privilege Management
CVE-2021-31360
CWE-269 Low
No
No
15.1R7-S10, 17.4R3-S5, 18.3R3-S5, 18.4R3-S9, 19.1R3-S6, 19.2R1-S7, 19.2R3-S3, 19.3R2-S6, 19.3R3-S3, 19.4R3-S6, 20.1R2-S2, 20.1R3-S1, 20.2R3-S2, 20.3R3, 20.4R2-S1, 20.4R3, 21.1R1-S1, 21.1R2, 21.1R3, 21.2R1 18.10.2021 SB2021101808


Showing elements 1 - 20 out of 72