Known vulnerabilities in Junos OS Evolved - page 2
Vendor:
Juniper Networks, Inc.
Software:
Junos OS Evolved
Software CPE:
cpe:2.3:o:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*
Website:
https://www.juniper.net/us/en/
Total vulnerabilities:
293
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
24.4R2-S4-EVO
20.2R1-S1-EVO
25.2R2-S1-EVO
23.2R2-S7-EVO
24.2R2-S5-EVO
23.4R2-S8-EVO
25.4R1-S2-EVO
26.2R1-EVO
25.4R2-EVO
25.4R1-S1-EVO
24.2R2-S4-EVO
24.4R2-S3-EVO
25.2R1-S2-EVO
24.1R2-EVO
21.4R3-S12-EVO
25.2R2-EVO
22.4R3-S9-EVO
23.2R2-S6-EVO
23.4R2-S7-EVO
25.4R1-EVO
24.4R2-S2-EVO
23.4R2-S6-EVO
24.2R2-S3-EVO
23.2R2-S5-EVO
22.4R3-S8-EVO
24.4R1-S1-EVO
25.2R1-S1-EVO
24.2R2-S2-EVO
25.1R1-EVO
24.4R2-EVO
23.4R2-S5-EVO
23.2R2-S4-EVO
22.2R3-S7-EVO
25.2R1-EVO
24.4R1-S3-EVO
24.2R2-S1-EVO
24.4R2-S1-EVO
22.4R3-S7-EVO
24.4R1-S2-EVO
22.2R3-S6-EVO
23.4R2-S4-EVO
22.4R3-S6-EVO
21.4R3-S10-EVO
21.2R3-S9-EVO
24.2R1-S1-EVO
22.3R3-S4-EVO
24.4R1-EVO
24.2R2-EVO
24.2R1-S2-EVO
23.4R2-S3-EVO
23.2R2-S3-EVO
22.4R3-S5-EVO
22.2R3-S5-EVO
21.4R3-S9-EVO
22.4R3-S4-EVO
23.2R2-S2-EVO
23.4R2-S2-EVO
23.4R2-S1-EVO
22.4R3-S3-EVO
21.4R3-S8-EVO
24.2R1-EVO
22.1R3-S6-EVO
23.4R1-S2-EVO
23.2R2-S1-EVO
22.4R3-S2-EVO
21.4R3-S7-EVO
23.4R1-S1-EVO
22.3R3-S3-EVO
22.2R3-S4-EVO
21.2R3-S8-EVO
23.4R1-EVO
24.1R1-EVO
23.4R2-EVO
22.4R3-S1-EVO
20.4R3-S10-EVO
19.4R3-S13-EVO
22.3R3-S2-EVO
21.2R3-S7-EVO
22.1R3-S5-EVO
21.4R3-S6-EVO
23.2R1-S2-EVO
20.4R3-S9-EVO
22.2R3-S3-EVO
20.2R3-S2-EVO
20.2R3-S1-EVO
20.2R3-EVO
19.4R3-EVO
19.3R3-EVO
19.2R3-EVO
21.4R3-S5-EVO
23.3R1-EVO
23.2R2-EVO
22.4R2-S2-EVO
23.3R3-EVO
23.2R1-S1-EVO
22.4R1-S1-EVO
22.3R2-S1-EVO
22.3R1-S2-EVO
22.2R3-S1-EVO
22.2R2-S2-EVO
22.2R1-S1-EVO
22.1R3-S2-EVO
22.1R3-S1-EVO
22.1R2-S1-EVO
22.1R1-S1-EVO
21.4R2-S2-EVO
21.3R3-S3-EVO
21.3R2-S2-EVO
21.3R2-S1-EVO
21.3R1-S1-EVO
21.2R3-S3-EVO
21.2R2-S2-EVO
21.2R1-S2-EVO
21.1R3-S3-EVO
21.1R1-S1-EVO
20.4R2-S1-EVO
20.4R1-S2-EVO
20.4R1-S1-EVO
18.3R1-EVO
21.4R3-S2-EVO
22.4R1-S2-EVO
22.3R3-EVO
21.4R3-S3-EVO
23.1R1-EVO
22.4R2-EVO
22.1R3-S3-EVO
21.3R3-S4-EVO
23.2R1-EVO
23.1R2-EVO
23.1R1-S1-EVO
22.4R3-EVO
22.4R2-S1-EVO
22.3R3-S1-EVO
22.3R2-S2-EVO
22.2R3-S2-EVO
22.1R3-S4-EVO
21.4R3-S4-EVO
21.3R3-S5-EVO
21.2R3-S6-EVO
20.4R3-S8-EVO
20.3-EVO
22.2-EVO
22.2R2-S1-EVO
22.1-EVO
21.3-EVO
22.2R3-EVO
21.4R3-S1-EVO
21.2R3-S5-EVO
21.1R3-S4-EVO
20.4R3-S7-EVO
20.2R2-EVO
20.1R3-EVO
21.3R3-S1-EVO
21.2R3-S4-EVO
20.4R3-S6-EVO
22.4R1-EVO
22.3R2-EVO
22.3R1-S1-EVO
21.4R2-S1-EVO
21.4R1-S2-EVO
21.2R2-S1-EVO
21.1R3-EVO
22.1R3-EVO
22.1R1-S2-EVO
22.3R1-EVO
22.2R2-EVO
21.3R3-S2-EVO
21.2R3-S1-EVO
20.4R3-S5-EVO
20.2R3-S3-EVO
21.4R1-S1-EVO
21.2R3-S2-EVO
21.1R3-S2-EVO
21.4R3-EVO
22.2R1-EVO
22.1R2-EVO
20.4R3-S3-EVO
20.4R3-S4-EVO
22.1R1-EVO
21.4R2-EVO
21.3R3-EVO
21.2R1-S1-EVO
21.1R3-S1-EVO
21.4R1-EVO
21.3R2-EVO
21.2R3-EVO
20.4R3-S2-EVO
20.1R1-EVO
21.2R2-EVO
20.4R3-EVO
20.4R2-S3-EVO
21.2-EVO
21.1-EVO
21.3R1-EVO
20.4R3-S1-EVO
21.1
20.4
20.3R2-S1-EVO
20.1R2-EVO
20.4R2-S2-EVO
21.2R1-EVO
21.1R2-EVO
21.1R1-EVO
20.4R2-EVO
20.3R1-EVO
20.1R2-S4-EVO
20.3
20.2
20.1
19.4
20.2R2-S1-EVO
20.1R2-S3-EVO
19.4R2-S3-EVO
19.1R1-EVO
20.3R1-S2-EVO
20.1R1-S4-EVO
19.3R2-S5-EVO
20.1R2-S1-EVO
20.1R1-S2-EVO
19.4R2-S2-EVO
20.4R1-EVO
20.3R2-EVO
20.3R1-S1-EVO
20.2R1-EVO
18.4R1-EVO
Vulnerabilities (293)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU121702 - Use After Free CVE-2026-21908 |
CWE-416 | Medium | 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S3-EVO, 24.4R2-S1-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, 25.4R1-EVO | 20.01.2026 |
SB2026012064 |
||
| #VU121700 - Incorrect Calculation CVE-2026-21911 |
CWE-682 | Medium | 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO | 20.01.2026 |
SB2026012062 |
||
| #VU121682 - Untrusted Pointer Dereference CVE-2025-59959 |
CWE-822 | Low | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO | 20.01.2026 |
SB2026012022 |
||
| #VU121681 - Incorrect Permission Assignment for Critical Resource CVE-2025-59961 |
CWE-732 | Low | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 20.01.2026 |
SB2026012021 |
||
| #VU121680 - Use After Free CVE-2026-21921 |
CWE-416 | Medium | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-EVO, 24.2R1-EVO | 20.01.2026 |
SB2026012020 |
||
| #VU121679 - Missing release of memory after effective lifetime CVE-2026-21909 |
CWE-401 | Medium | 23.2R2-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.1R2-EVO, 24.2R1-EVO | 20.01.2026 |
SB2026012019 |
||
| #VU121668 - Improper Check for Unusual or Exceptional Conditions CVE-2025-60011 |
CWE-754 | Medium | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO | 19.01.2026 |
SB2026011998 |
||
| #VU121667 - Improper Check for Unusual or Exceptional Conditions CVE-2025-59960 |
CWE-754 | Medium | 21.4R3-S12-EVO, 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 19.01.2026 |
SB2026011997 |
||
| #VU121662 - Buffer over-read CVE-2025-60003 |
CWE-126 | Medium | 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO | 19.01.2026 |
SB2026011987 |
||
| #VU116940 - Resource exhaustion CVE-2025-52961 |
CWE-400 | Medium | 23.2R2-S4-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-S2-EVO, 24.4R2-EVO, 25.2R1-EVO | 13.10.2025 |
SB20251013100 |
||
| #VU116938 - Improper Check for Unusual or Exceptional Conditions CVE-2025-59958 |
CWE-754 | Medium | 22.4R3-EVO, 23.2R2-EVO, 23.4R1-EVO | 13.10.2025 |
SB2025101398 |
||
| #VU116937 - Not Using Password Aging CVE-2025-60010 |
CWE-262 | Medium | 22.4R3-S8-EVO, 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO | 13.10.2025 |
SB2025101397 |
||
| #VU116935 - Access of Uninitialized Pointer CVE-2025-59962 |
CWE-824 | Medium | 22.3R3-S3-EVO, 22.4R3-EVO, 23.2R2-EVO, 23.4R1-EVO | 13.10.2025 |
SB2025101395 |
||
| #VU116934 - NULL Pointer Dereference CVE-2025-59967 |
CWE-476 | Medium | 23.2R2-S4-EVO, 23.4R2-EVO, 24.2R1-EVO | 13.10.2025 |
SB2025101393 |
||
| #VU116933 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-60006 |
CWE-78 | Low | 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO | 13.10.2025 |
SB2025101392 |
||
| #VU116931 - Improper Check for Unusual or Exceptional Conditions CVE-2025-60004 |
CWE-754 | Medium | 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO | 13.10.2025 |
SB2025101390 |
||
| #VU113180 - Use of Incorrect Operator CVE-2025-52985 |
CWE-480 | Medium | 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO | 23.07.2025 |
SB2025072339 |
||
| #VU113070 - Reachable Assertion CVE-2025-52958 |
CWE-617 | Medium | 22.2R3-S6-EVO, 22.4R3-S6-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO | 18.07.2025 |
SB2025071858 |
||
| #VU113068 - Use After Free CVE-2025-52946 |
CWE-416 | Medium | 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO | 18.07.2025 |
SB2025071855 |
||
| #VU100611 - Missing release of memory after effective lifetime CVE-2024-50302 |
CWE-401 | Medium | 22.4R3-S9-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S3-EVO, 24.4R2-S1-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO | 19.11.2024 |
SB2024111922 SB2024112401 SB2024121358 and 128 more |
Showing elements 21 - 40 out of 293