Known vulnerabilities in Junos OS Evolved - page 11
Vendor:
Juniper Networks, Inc.
Software:
Junos OS Evolved
Software CPE:
cpe:2.3:o:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*
Website:
https://www.juniper.net/us/en/
Total vulnerabilities:
293
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
24.4R2-S4-EVO
20.2R1-S1-EVO
25.2R2-S1-EVO
23.2R2-S7-EVO
24.2R2-S5-EVO
23.4R2-S8-EVO
25.4R1-S2-EVO
26.2R1-EVO
25.4R2-EVO
25.4R1-S1-EVO
24.2R2-S4-EVO
24.4R2-S3-EVO
25.2R1-S2-EVO
24.1R2-EVO
21.4R3-S12-EVO
25.2R2-EVO
22.4R3-S9-EVO
23.2R2-S6-EVO
23.4R2-S7-EVO
25.4R1-EVO
24.4R2-S2-EVO
23.4R2-S6-EVO
24.2R2-S3-EVO
23.2R2-S5-EVO
22.4R3-S8-EVO
24.4R1-S1-EVO
25.2R1-S1-EVO
24.2R2-S2-EVO
25.1R1-EVO
24.4R2-EVO
23.4R2-S5-EVO
23.2R2-S4-EVO
22.2R3-S7-EVO
25.2R1-EVO
24.4R1-S3-EVO
24.2R2-S1-EVO
24.4R2-S1-EVO
22.4R3-S7-EVO
24.4R1-S2-EVO
22.2R3-S6-EVO
23.4R2-S4-EVO
22.4R3-S6-EVO
21.4R3-S10-EVO
21.2R3-S9-EVO
24.2R1-S1-EVO
22.3R3-S4-EVO
24.4R1-EVO
24.2R2-EVO
24.2R1-S2-EVO
23.4R2-S3-EVO
23.2R2-S3-EVO
22.4R3-S5-EVO
22.2R3-S5-EVO
21.4R3-S9-EVO
22.4R3-S4-EVO
23.2R2-S2-EVO
23.4R2-S2-EVO
23.4R2-S1-EVO
22.4R3-S3-EVO
21.4R3-S8-EVO
24.2R1-EVO
22.1R3-S6-EVO
23.4R1-S2-EVO
23.2R2-S1-EVO
22.4R3-S2-EVO
21.4R3-S7-EVO
23.4R1-S1-EVO
22.3R3-S3-EVO
22.2R3-S4-EVO
21.2R3-S8-EVO
23.4R1-EVO
24.1R1-EVO
23.4R2-EVO
22.4R3-S1-EVO
20.4R3-S10-EVO
19.4R3-S13-EVO
22.3R3-S2-EVO
21.2R3-S7-EVO
22.1R3-S5-EVO
21.4R3-S6-EVO
23.2R1-S2-EVO
20.4R3-S9-EVO
22.2R3-S3-EVO
20.2R3-S2-EVO
20.2R3-S1-EVO
20.2R3-EVO
19.4R3-EVO
19.3R3-EVO
19.2R3-EVO
21.4R3-S5-EVO
23.3R1-EVO
23.2R2-EVO
22.4R2-S2-EVO
23.3R3-EVO
23.2R1-S1-EVO
22.4R1-S1-EVO
22.3R2-S1-EVO
22.3R1-S2-EVO
22.2R3-S1-EVO
22.2R2-S2-EVO
22.2R1-S1-EVO
22.1R3-S2-EVO
22.1R3-S1-EVO
22.1R2-S1-EVO
22.1R1-S1-EVO
21.4R2-S2-EVO
21.3R3-S3-EVO
21.3R2-S2-EVO
21.3R2-S1-EVO
21.3R1-S1-EVO
21.2R3-S3-EVO
21.2R2-S2-EVO
21.2R1-S2-EVO
21.1R3-S3-EVO
21.1R1-S1-EVO
20.4R2-S1-EVO
20.4R1-S2-EVO
20.4R1-S1-EVO
18.3R1-EVO
21.4R3-S2-EVO
22.4R1-S2-EVO
22.3R3-EVO
21.4R3-S3-EVO
23.1R1-EVO
22.4R2-EVO
22.1R3-S3-EVO
21.3R3-S4-EVO
23.2R1-EVO
23.1R2-EVO
23.1R1-S1-EVO
22.4R3-EVO
22.4R2-S1-EVO
22.3R3-S1-EVO
22.3R2-S2-EVO
22.2R3-S2-EVO
22.1R3-S4-EVO
21.4R3-S4-EVO
21.3R3-S5-EVO
21.2R3-S6-EVO
20.4R3-S8-EVO
20.3-EVO
22.2-EVO
22.2R2-S1-EVO
22.1-EVO
21.3-EVO
22.2R3-EVO
21.4R3-S1-EVO
21.2R3-S5-EVO
21.1R3-S4-EVO
20.4R3-S7-EVO
20.2R2-EVO
20.1R3-EVO
21.3R3-S1-EVO
21.2R3-S4-EVO
20.4R3-S6-EVO
22.4R1-EVO
22.3R2-EVO
22.3R1-S1-EVO
21.4R2-S1-EVO
21.4R1-S2-EVO
21.2R2-S1-EVO
21.1R3-EVO
22.1R3-EVO
22.1R1-S2-EVO
22.3R1-EVO
22.2R2-EVO
21.3R3-S2-EVO
21.2R3-S1-EVO
20.4R3-S5-EVO
20.2R3-S3-EVO
21.4R1-S1-EVO
21.2R3-S2-EVO
21.1R3-S2-EVO
21.4R3-EVO
22.2R1-EVO
22.1R2-EVO
20.4R3-S3-EVO
20.4R3-S4-EVO
22.1R1-EVO
21.4R2-EVO
21.3R3-EVO
21.2R1-S1-EVO
21.1R3-S1-EVO
21.4R1-EVO
21.3R2-EVO
21.2R3-EVO
20.4R3-S2-EVO
20.1R1-EVO
21.2R2-EVO
20.4R3-EVO
20.4R2-S3-EVO
21.2-EVO
21.1-EVO
21.3R1-EVO
20.4R3-S1-EVO
21.1
20.4
20.3R2-S1-EVO
20.1R2-EVO
20.4R2-S2-EVO
21.2R1-EVO
21.1R2-EVO
21.1R1-EVO
20.4R2-EVO
20.3R1-EVO
20.1R2-S4-EVO
20.3
20.2
20.1
19.4
20.2R2-S1-EVO
20.1R2-S3-EVO
19.4R2-S3-EVO
19.1R1-EVO
20.3R1-S2-EVO
20.1R1-S4-EVO
19.3R2-S5-EVO
20.1R2-S1-EVO
20.1R1-S2-EVO
19.4R2-S2-EVO
20.4R1-EVO
20.3R2-EVO
20.3R1-S1-EVO
20.2R1-EVO
18.4R1-EVO
Vulnerabilities (293)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU81492 - Resource exhaustion CVE-2023-22400 |
CWE-400 | Medium | 20.4R3-S3-EVO, 21.2R3-S4-EVO, 21.4R2-EVO, 22.1R1-EVO | 04.10.2023 |
SB2023011165 |
||
| #VU75134 - Missing release of memory after effective lifetime CVE-2023-28982 |
CWE-401 | Medium | 20.4R3-S6-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO | 14.04.2023 |
SB2023041445 |
||
| #VU75131 - Improper input validation CVE-2023-28981 |
CWE-20 | Low | 20.4R3-S6-EVO, 21.3R3-EVO, 21.4R2-EVO, 22.1R2-EVO, 22.2R1-EVO | 14.04.2023 |
SB2023041444 |
||
| #VU75130 - Insecure Default Variable Initialization CVE-2023-28978 |
CWE-453 | Medium | 20.4R3-S7-EVO, 21.1R3-S4-EVO, 21.2R3-S5-EVO, 21.4R3-S1-EVO, 22.2R2-EVO, 22.3R1-EVO | 14.04.2023 |
SB2023041443 |
||
| #VU75124 - Incorrect Default Permissions CVE-2023-28966 |
CWE-276 | Low | 20.4R3-S5-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO | 14.04.2023 |
SB2023041442 |
||
| #VU75121 - Improper Handling of Length Parameter Inconsistency CVE-2023-28964 |
CWE-130 | Medium | 20.1R3-EVO, 20.2R2-EVO, 20.3R2-EVO, 20.4R1-EVO | 14.04.2023 |
SB2023041441 |
||
| #VU75118 - Use of Uninitialized Resource CVE-2023-28967 |
CWE-908 | Medium | 21.4R3-EVO, 22.1R3-EVO, 22.2R2-EVO, 22.3R1-EVO | 14.04.2023 |
SB2023041440 |
||
| #VU75117 - Improper Authorization CVE-2023-28973 |
CWE-285 | Low | 20.4R3-S5-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-S2-EVO, 21.4R2-EVO, 22.1R1-EVO | 14.04.2023 |
SB2023041439 |
||
| #VU75116 - Incorrect Permission Assignment for Critical Resource CVE-2023-28960 |
CWE-732 | Low | 20.4R3-S5-EVO, 21.2R3-EVO, 21.3R3-EVO, 21.4R2-EVO, 22.1R1-EVO | 14.04.2023 |
SB2023041438 |
||
| #VU75092 - Use After Free CVE-2023-28980 |
CWE-416 | Low | 20.4R3-S6-EVO, 21.2R3-S4-EVO, 21.3R3-S1-EVO, 21.4R2-S1-EVO, 21.4R3-EVO, 22.1R2-EVO, 22.2R1-EVO | 13.04.2023 |
SB2023041341 |
||
| #VU75048 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-28983 |
CWE-78 | Medium | 22.2R1-EVO, 22.3R1-EVO | 12.04.2023 |
SB2023041265 |
||
| #VU82486 - Use After Free CVE-2023-22402 |
CWE-416 | Medium | 21.3R3-EVO, 21.4R2-EVO, 22.1R2-EVO, 22.2R1-S1-EVO, 22.2R2-EVO, 22.3R1-EVO | 11.01.2023 |
SB2023011184 |
||
| #VU82477 - Improper Validation of Array Index CVE-2023-22401 |
CWE-129 | Medium | 21.4R2-S1-EVO, 22.1R3-EVO, 22.2R1-S1-EVO, 22.2R2-EVO | 11.01.2023 |
SB2023011175 |
||
| #VU82476 - Access of Uninitialized Pointer CVE-2023-22398 |
CWE-824 | Medium | 20.4R3-S4-EVO, 21.1R2-EVO, 21.2R1-EVO | 11.01.2023 |
SB2023011174 |
||
| #VU82474 - Missing release of memory after effective lifetime CVE-2023-22406 |
CWE-401 | Medium | 20.4R3-S4-EVO, 21.4R2-S1-EVO, 21.4R3-EVO, 22.1R2-EVO, 22.2R1-EVO | 11.01.2023 |
SB2023011172 |
||
| #VU82471 - Incomplete cleanup CVE-2023-22407 |
CWE-459 | Medium | 19.2R3-EVO, 19.3R3-EVO, 19.4R3-EVO, 20.1R3-EVO, 20.2R2-EVO, 20.3R1-EVO | 11.01.2023 |
SB2023011169 |
||
| #VU82470 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2023-22397 |
CWE-367 | Medium | 20.4R3-S4-EVO, 21.3R3-S1-EVO, 21.4R2-S2-EVO, 21.4R3-EVO, 22.1R1-S2-EVO, 22.1R2-EVO, 22.1R3-EVO, 22.2R1-S1-EVO, 22.2R2-EVO, 22.3R1-EVO | 11.01.2023 |
SB2023011168 |
||
| #VU70509 - Improper input validation CVE-2022-22184 |
CWE-20 | Medium | 22.3R1-S1-EVO, 22.3R2-EVO, 22.4R1-EVO | 28.12.2022 |
SB2022122803 |
||
| #VU62768 - Uncontrolled Memory Allocation CVE-2022-1473 |
CWE-789 | Low | 22.1R3-EVO, 22.2R1-EVO | 03.05.2022 |
SB2022050315 SB2022050436 SB2022050532 and 18 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | 22.1R3-EVO, 22.2R1-EVO | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
Showing elements 201 - 220 out of 293