Known vulnerabilities in Junos OS Evolved
Vendor:
Juniper Networks, Inc.
Software:
Junos OS Evolved
Software CPE:
cpe:2.3:o:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*
Website:
https://www.juniper.net/us/en/
Total vulnerabilities:
293
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
24.4R2-S4-EVO
20.2R1-S1-EVO
25.2R2-S1-EVO
23.2R2-S7-EVO
24.2R2-S5-EVO
23.4R2-S8-EVO
25.4R1-S2-EVO
26.2R1-EVO
25.4R2-EVO
25.4R1-S1-EVO
24.2R2-S4-EVO
24.4R2-S3-EVO
25.2R1-S2-EVO
24.1R2-EVO
21.4R3-S12-EVO
25.2R2-EVO
22.4R3-S9-EVO
23.2R2-S6-EVO
23.4R2-S7-EVO
25.4R1-EVO
24.4R2-S2-EVO
23.4R2-S6-EVO
24.2R2-S3-EVO
23.2R2-S5-EVO
22.4R3-S8-EVO
24.4R1-S1-EVO
25.2R1-S1-EVO
24.2R2-S2-EVO
25.1R1-EVO
24.4R2-EVO
23.4R2-S5-EVO
23.2R2-S4-EVO
22.2R3-S7-EVO
25.2R1-EVO
24.4R1-S3-EVO
24.2R2-S1-EVO
24.4R2-S1-EVO
22.4R3-S7-EVO
24.4R1-S2-EVO
22.2R3-S6-EVO
23.4R2-S4-EVO
22.4R3-S6-EVO
21.4R3-S10-EVO
21.2R3-S9-EVO
24.2R1-S1-EVO
22.3R3-S4-EVO
24.4R1-EVO
24.2R2-EVO
24.2R1-S2-EVO
23.4R2-S3-EVO
23.2R2-S3-EVO
22.4R3-S5-EVO
22.2R3-S5-EVO
21.4R3-S9-EVO
22.4R3-S4-EVO
23.2R2-S2-EVO
23.4R2-S2-EVO
23.4R2-S1-EVO
22.4R3-S3-EVO
21.4R3-S8-EVO
24.2R1-EVO
22.1R3-S6-EVO
23.4R1-S2-EVO
23.2R2-S1-EVO
22.4R3-S2-EVO
21.4R3-S7-EVO
23.4R1-S1-EVO
22.3R3-S3-EVO
22.2R3-S4-EVO
21.2R3-S8-EVO
23.4R1-EVO
24.1R1-EVO
23.4R2-EVO
22.4R3-S1-EVO
20.4R3-S10-EVO
19.4R3-S13-EVO
22.3R3-S2-EVO
21.2R3-S7-EVO
22.1R3-S5-EVO
21.4R3-S6-EVO
23.2R1-S2-EVO
20.4R3-S9-EVO
22.2R3-S3-EVO
20.2R3-S2-EVO
20.2R3-S1-EVO
20.2R3-EVO
19.4R3-EVO
19.3R3-EVO
19.2R3-EVO
21.4R3-S5-EVO
23.3R1-EVO
23.2R2-EVO
22.4R2-S2-EVO
23.3R3-EVO
23.2R1-S1-EVO
22.4R1-S1-EVO
22.3R2-S1-EVO
22.3R1-S2-EVO
22.2R3-S1-EVO
22.2R2-S2-EVO
22.2R1-S1-EVO
22.1R3-S2-EVO
22.1R3-S1-EVO
22.1R2-S1-EVO
22.1R1-S1-EVO
21.4R2-S2-EVO
21.3R3-S3-EVO
21.3R2-S2-EVO
21.3R2-S1-EVO
21.3R1-S1-EVO
21.2R3-S3-EVO
21.2R2-S2-EVO
21.2R1-S2-EVO
21.1R3-S3-EVO
21.1R1-S1-EVO
20.4R2-S1-EVO
20.4R1-S2-EVO
20.4R1-S1-EVO
18.3R1-EVO
21.4R3-S2-EVO
22.4R1-S2-EVO
22.3R3-EVO
21.4R3-S3-EVO
23.1R1-EVO
22.4R2-EVO
22.1R3-S3-EVO
21.3R3-S4-EVO
23.2R1-EVO
23.1R2-EVO
23.1R1-S1-EVO
22.4R3-EVO
22.4R2-S1-EVO
22.3R3-S1-EVO
22.3R2-S2-EVO
22.2R3-S2-EVO
22.1R3-S4-EVO
21.4R3-S4-EVO
21.3R3-S5-EVO
21.2R3-S6-EVO
20.4R3-S8-EVO
20.3-EVO
22.2-EVO
22.2R2-S1-EVO
22.1-EVO
21.3-EVO
22.2R3-EVO
21.4R3-S1-EVO
21.2R3-S5-EVO
21.1R3-S4-EVO
20.4R3-S7-EVO
20.2R2-EVO
20.1R3-EVO
21.3R3-S1-EVO
21.2R3-S4-EVO
20.4R3-S6-EVO
22.4R1-EVO
22.3R2-EVO
22.3R1-S1-EVO
21.4R2-S1-EVO
21.4R1-S2-EVO
21.2R2-S1-EVO
21.1R3-EVO
22.1R3-EVO
22.1R1-S2-EVO
22.3R1-EVO
22.2R2-EVO
21.3R3-S2-EVO
21.2R3-S1-EVO
20.4R3-S5-EVO
20.2R3-S3-EVO
21.4R1-S1-EVO
21.2R3-S2-EVO
21.1R3-S2-EVO
21.4R3-EVO
22.2R1-EVO
22.1R2-EVO
20.4R3-S3-EVO
20.4R3-S4-EVO
22.1R1-EVO
21.4R2-EVO
21.3R3-EVO
21.2R1-S1-EVO
21.1R3-S1-EVO
21.4R1-EVO
21.3R2-EVO
21.2R3-EVO
20.4R3-S2-EVO
20.1R1-EVO
21.2R2-EVO
20.4R3-EVO
20.4R2-S3-EVO
21.2-EVO
21.1-EVO
21.3R1-EVO
20.4R3-S1-EVO
21.1
20.4
20.3R2-S1-EVO
20.1R2-EVO
20.4R2-S2-EVO
21.2R1-EVO
21.1R2-EVO
21.1R1-EVO
20.4R2-EVO
20.3R1-EVO
20.1R2-S4-EVO
20.3
20.2
20.1
19.4
20.2R2-S1-EVO
20.1R2-S3-EVO
19.4R2-S3-EVO
19.1R1-EVO
20.3R1-S2-EVO
20.1R1-S4-EVO
19.3R2-S5-EVO
20.1R2-S1-EVO
20.1R1-S2-EVO
19.4R2-S2-EVO
20.4R1-EVO
20.3R2-EVO
20.3R1-S1-EVO
20.2R1-EVO
18.4R1-EVO
Vulnerabilities (293)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137150 - Out-of-bounds write CVE-2026-33799 |
CWE-787 | Medium | 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 23.2R2-EVO, 23.4R2-EVO, 24.2R1-EVO | 08.07.2026 |
SB2026070870 |
||
| #VU137149 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-57029 |
CWE-362 | Medium | 23.4R2-S7-EVO, 24.2R2-S5-EVO, 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO | 08.07.2026 |
SB2026070869 |
||
| #VU137146 - Return of pointer value outside of expected range CVE-2026-57025 |
CWE-466 | Low | 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R2-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO | 08.07.2026 |
SB2026070860 |
||
| #VU137145 - Improper Restriction of Communication Channel to Intended Endpoints CVE-2026-33803 |
CWE-923 | Medium | 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R2-S5-EVO, 24.4R2-S4-EVO, 25.2R2-S1-EVO, 25.4R1-S2-EVO, 25.4R2-EVO, 26.2R1-EVO | 08.07.2026 |
SB2026070859 |
||
| #VU137138 - NULL Pointer Dereference CVE-2026-21901 |
CWE-476 | Low | 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R1-EVO | 08.07.2026 |
SB2026070852 |
||
| #VU137136 - Improper Restriction of Communication Channel to Intended Endpoints CVE-2026-57028 |
CWE-923 | Medium | 23.2R2-EVO, 23.4R1-EVO | 08.07.2026 |
SB2026070850 |
||
| #VU137134 - Improper Check for Unusual or Exceptional Conditions CVE-2026-33794 |
CWE-754 | Medium | 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO | 08.07.2026 |
SB2026070848 |
||
| #VU137132 - Improper Check for Unusual or Exceptional Conditions CVE-2026-33801 |
CWE-754 | Medium | 25.2R2-EVO, 25.4R1-EVO | 08.07.2026 |
SB2026070846 |
||
| #VU130704 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-21919 |
CWE-362 | Low | 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO | 08.05.2026 |
SB2026050828 |
||
| #VU130702 - Command injection CVE-2026-33791 |
CWE-77 | Low | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S7-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 08.05.2026 |
SB2026050826 |
||
| #VU130697 - Execution with Unnecessary Privileges CVE-2026-33793 |
CWE-250 | Low | 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO | 08.05.2026 |
SB2026050824 |
||
| #VU130696 - Missing Authorization CVE-2026-33776 |
CWE-862 | Low | 23.2R2-S6-EVO, 23.4R2-S6-EVO, 24.2R2-S4-EVO, 24.4R2-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 08.05.2026 |
SB2026050820 |
||
| #VU130694 - Missing release of memory after effective lifetime CVE-2026-33780 |
CWE-401 | Medium | 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO | 08.05.2026 |
SB2026050819 |
||
| #VU130693 - Missing Authentication for Critical Function CVE-2026-33788 |
CWE-306 | Low | 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-EVO, 23.4R1-EVO | 08.05.2026 |
SB2026050818 |
||
| #VU130692 - Improper input validation CVE-2026-33797 |
CWE-20 | Low | 25.2R2-EVO, 25.4R1-EVO | 08.05.2026 |
SB2026050816 |
||
| #VU130689 - Stack-based buffer overflow CVE-2025-59969 |
CWE-121 | Low | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-EVO, 24.2R2-EVO, 24.4R2-EVO, 25.2R1-EVO | 08.05.2026 |
SB2026050813 |
||
| #VU125520 - Function Call With Incorrect Argument Type CVE-2026-33783 |
CWE-686 | Medium | 22.4R3-S9-EVO, 23.2R2-S6-EVO, 23.4R2-S7-EVO, 24.2R2-S4-EVO, 24.4R2-S2-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, 25.4R1-EVO | 08.04.2026 |
SB20260408178 |
||
| #VU123294 - Incorrect Permission Assignment for Critical Resource CVE-2026-21902 |
CWE-732 | Critical | 25.4R1-S1-EVO, 25.4R2-EVO, 26.2R1-EVO | 26.02.2026 |
SB2026022617 |
||
| #VU65671 - Out-of-bounds write CVE-2022-24805 |
CWE-787 | Medium | 23.2R2-S6-EVO, 23.4R2-S8-EVO | 21.07.2022 |
SB2022072138 SB2022072139 SB2022080133 and 19 more |
||
| #VU24718 - Memory corruption CVE-2020-7450 |
CWE-119 | High | 22.4R3-S9-EVO, 23.2R2-S5-EVO, 23.4R2-S8-EVO, 24.2R2-S3-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 29.01.2020 |
SB2020012902 SB2020020210 SB2022110215 and 1 more |
Showing elements 1 - 20 out of 293