Netzwerksicherheit
Schwachstellen bei Juniper Networks: jede Meldung, die die Register seinen Produkten zuordnen
Kurz gesagt
80 Schwachstellenmeldungen in diesem Bestand sind Produkten von Juniper Networks zugeordnet. Sie reichen von März 2022 bis Juli 2026. 7 davon stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen. Jeder Eintrag unten verlinkt auf das Register, das ihn veröffentlicht hat.
Zugeordnet
80
an ein benanntes Produkt gebunden
Aktiv ausgenutzt
7
im CISA-Katalog geführt
Als kritisch eingestuft
10
Einstufung des Registers
Zuletzt geprüft
17. Juli 2026
Quellen neu abgefragt
Warum diese Liste kürzer ist als ein CVE-Spiegel
Die Register werden über Stichworte durchsucht, also liefert die Suche nach einem Firmennamen auch Meldungen zurück, die diesen Namen nur erwähnen. Ein Spiegel veröffentlicht sie mit. Diese Seite nicht: Ein Eintrag erscheint erst, wenn das Register selbst ihn an ein Produkt von Juniper Networks bindet, über einen Verweis auf eine Adresse des Anbieters, über Juniper Networks als die Stelle, die die CVE-Nummer vergeben hat, oder über die Liste der betroffenen Produkte.
0 Einträge haben diese Hürde nicht genommen und werden nicht angezeigt. Das ist der Unterschied, und er ist gewollt: Eine Seite, die die Schwachstelle eines anderen Unternehmens unter dieser Überschrift führt, ist auf die Art falsch, die am meisten kostet.
73 der 80 Einträge tragen einen CVSS-Basiswert aus dem Register. Wo keiner veröffentlicht ist, steht keiner, und geschätzt wird nichts.
Die vollständige Liste, bekannt ausgenutzte und neueste zuerst
Führen mehrere Register dieselbe Meldung, steht sie einmal da, mit einem Link auf jedes. So wird dieselbe Schwachstelle nicht doppelt gezählt. Einträge aus dem CISA-Katalog bekannt ausgenutzter Schwachstellen stehen oben, weil das der eine Hinweis auf dieser Seite ist, der ändert, was als Nächstes zu tun ist.
- CVE-2025-21590criticalAktiv ausgenutzt13. März 2025
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
- CVE-2023-36844criticalAktiv ausgenutzt13. Nov. 2023
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
- CVE-2023-36845criticalAktiv ausgenutzt13. Nov. 2023
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
- CVE-2023-36846criticalAktiv ausgenutzt13. Nov. 2023
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
- CVE-2023-36847criticalAktiv ausgenutzt13. Nov. 2023
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
- CVE-2023-36851criticalAktiv ausgenutzt13. Nov. 2023
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
- CVE-2020-1631criticalAktiv ausgenutzt25. März 2022
Juniper Junos OS Path Traversal Vulnerability
- WID-SEC-2026-2257highCVSS 8.610. Juli 2026
Affected products: Juniper JUNOS, Juniper QFX Series, Juniper EX Series, Juniper SRX Series
- CVE-2026-57054mediumCVSS 6.909. Juli 2026
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to…
- CVE-2026-57032highCVSS 7.109. Juli 2026
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low…
- CVE-2026-57031mediumCVSS 5.309. Juli 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass…
- CVE-2026-57030highCVSS 8.209. Juli 2026
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series…
- CVE-2026-57029mediumCVSS 6.009. Juli 2026
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a…
- CVE-2026-57028mediumCVSS 6.909. Juli 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license…
- CVE-2026-57027highCVSS 7.109. Juli 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated…
- CVE-2026-57026highCVSS 8.709. Juli 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated…
- CVE-2026-57025mediumCVSS 6.809. Juli 2026
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a…
- CVE-2026-57024mediumCVSS 6.909. Juli 2026
A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated…
- CVE-2026-57023highCVSS 8.709. Juli 2026
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated…
- CVE-2026-57022highCVSS 8.209. Juli 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an…
- CVE-2026-57021mediumCVSS 6.909. Juli 2026
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a…
- CVE-2026-57020highCVSS 7.109. Juli 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated…
- CVE-2026-57019highCVSS 7.109. Juli 2026
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent…
- CVE-2026-33803mediumCVSS 6.909. Juli 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a…
- CVE-2026-33802mediumCVSS 6.809. Juli 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
- CVE-2026-33801highCVSS 7.109. Juli 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…
- CVE-2026-33800highCVSS 7.109. Juli 2026
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a…
- CVE-2026-33799mediumCVSS 5.309. Juli 2026
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid…
- CVE-2026-33794highCVSS 8.209. Juli 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an…
- CVE-2026-21901mediumCVSS 6.709. Juli 2026
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating…
- WID-SEC-2026-1022highCVSS 10.010. Apr. 2026
Affected products: Juniper Apstra, Juniper JUNOS, Juniper QFX Series, Juniper MX Series
- CVE-2026-33791highCVSS 8.409. Apr. 2026
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI…
- CVE-2026-33787mediumCVSS 6.809. Apr. 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a…
- CVE-2026-33785mediumCVSS 6.309. Apr. 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will…
- CVE-2026-33784criticalCVSS 9.309. Apr. 2026
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take…
- CVE-2026-33783highCVSS 7.109. Apr. 2026
A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low…
- CVE-2026-33778highCVSS 8.709. Apr. 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an…
- CVE-2026-33776mediumCVSS 6.809. Apr. 2026
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information.
- CVE-2026-33774mediumCVSS 6.909. Apr. 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated…
- CVE-2026-33771criticalCVSS 9.109. Apr. 2026
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of…
- CVE-2025-13914highCVSS 7.009. Apr. 2026
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices.
- CVE-2026-33797highCVSS 7.109. Apr. 2026
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an…
- CVE-2026-33779highCVSS 8.309. Apr. 2026
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get…
- CVE-2026-33775highCVSS 7.109. Apr. 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an…
- CVE-2026-33782highCVSS 8.709. Apr. 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to…
- CVE-2026-33780highCVSS 7.109. Apr. 2026
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…
- CVE-2026-33773mediumCVSS 6.909. Apr. 2026
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an…
- CVE-2026-33786mediumCVSS 6.809. Apr. 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local…
- CVE-2026-21916highCVSS 7.009. Apr. 2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to…
- CVE-2026-33788highCVSS 8.509. Apr. 2026
A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated…
- CVE-2026-21919highCVSS 7.109. Apr. 2026
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a…
- CVE-2026-21915highCVSS 8.409. Apr. 2026
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to…
- CVE-2026-21904mediumCVSS 5.109. Apr. 2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list…
- CVE-2025-59969highCVSS 7.109. Apr. 2026
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on…
- CVE-2026-33793highCVSS 8.509. Apr. 2026
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root…
- CVE-2025-30650highCVSS 8.408. Apr. 2026
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards…
- WID-SEC-2026-0535criticalCVSS 10.004. März 2026
Affected products: Juniper JUNOS
- WID-SEC-2025-0393highCVSS 9.828. Jan. 2026
Affected products: Juniper Session Smart Router
- WID-SEC-2026-0117highCVSS 8.616. Jan. 2026
Affected products: Juniper JUNOS, Juniper Junos Space
- WID-SEC-2025-1519highCVSS 9.610. Okt. 2025
Affected products: Juniper MX Series, Juniper JUNOS, Juniper SRX Series, Juniper Security Director
- WID-SEC-2025-2238highCVSS 8.610. Okt. 2025
Affected products: Juniper JUNOS
- WID-SEC-2023-0063highCVSS 9.809. Okt. 2025
Affected products: Juniper Junos Space, Juniper Contrail Service Orchestration
- WID-SEC-2025-0794highCVSS 10.005. Sept. 2025
Affected products: Amazon Linux 2, SUSE Linux, Juniper Junos Space
- WID-SEC-2024-0064highCVSS 10.011. Apr. 2025
Affected products: Juniper Junos Space, Juniper MX Series, Juniper JUNOS, Juniper EX Series
- WID-SEC-2025-0777highCVSS 8.610. Apr. 2025
Affected products: Juniper JUNOS
- WID-SEC-2025-0552mediumCVSS 4.414. März 2025
Affected products: Juniper JUNOS
- WID-SEC-2025-0031highCVSS 8.609. Jan. 2025
Affected products: Juniper JUNOS
- WID-SEC-2024-3140highCVSS 9.809. Jan. 2025
Affected products: Juniper JUNOS, Juniper Junos Space
- WID-SEC-2024-1591mediumCVSS 7.512. Nov. 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-1500mediumCVSS 7.502. Juli 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-1082highCVSS 9.810. Mai 2024
Affected products: Juniper JUNOS
- WID-SEC-2024-0855highCVSS 8.817. Apr. 2024
Affected products: Juniper MX Series, Juniper JUNOS, Juniper QFX Series, Juniper EX Series
- WID-SEC-2024-0222highCVSS 8.826. Jan. 2024
Affected products: Juniper EX Series, Juniper JUNOS, Juniper SRX Series
- WID-SEC-2023-2636highCVSS 8.413. Okt. 2023
Affected products: Juniper MX Series, Juniper JUNOS, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-2092highCVSS 9.829. Sept. 2023
Affected products: Juniper EX Series, Juniper SRX Series, Juniper JUNOS
- WID-SEC-2023-2212mediumCVSS 7.530. Aug. 2023
Affected products: Juniper JUNOS
- WID-SEC-2023-1737highCVSS 10.013. Juli 2023
Affected products: Juniper JUNOS, Juniper MX Series, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-1527mediumCVSS 7.522. Juni 2023
Affected products: Juniper JUNOS
- WID-SEC-2023-0951highCVSS 9.817. Apr. 2023
Affected products: Juniper JUNOS, Juniper MX Series, Juniper SRX Series, Juniper QFX Series
- WID-SEC-2023-0083mediumCVSS 7.512. Jan. 2023
Affected products: Juniper JUNOS
Welche Register beigetragen haben
| Register | Betreiber | Einträge | Neuester Eintrag |
|---|---|---|---|
| European Vulnerability Database | ENISA, Europäische Union | 47 | 09. Juli 2026 |
| CERT-Bund Sicherheitshinweise | BSI, Bundesrepublik Deutschland | 26 | 10. Juli 2026 |
| Katalog bekannt ausgenutzter Schwachstellen | CISA, Vereinigte Staaten | 7 | 13. März 2025 |
Die Zahlen hier sind die rohen Registertreffer zu Juniper Networks, vor der Zuordnung. Genau deshalb sind sie größer als die Liste darüber.
Fragen, die diese Seite beantwortet
Wie viele Schwachstellen hat Juniper Networks?
80 Meldungen in diesem Bestand sind von einem Register einem Produkt von Juniper Networks zugeordnet. Das ist nicht dasselbe wie die Zahl der Schwachstellen in den Produkten, und die kennt keine öffentliche Quelle. Es ist die Zahl dessen, was gefunden, offengelegt und veröffentlicht wurde, und die hängt daran, wie intensiv die Produkte geprüft werden und wie offen der Anbieter damit umgeht.
Werden Schwachstellen in Produkten von Juniper Networks aktiv ausgenutzt?
7 der 80 Einträge stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen, der Lücken mit bestätigter Ausnutzung in freier Wildbahn führt. Sie stehen in der Liste oben. Ob einer davon Ihre Installation betrifft, hängt an den Versionen und Komponenten, die Sie betreiben.
Warum zeigt diese Seite weniger CVEs zu Juniper Networks als andere Seiten?
Weil eine Stichwortsuche nach einem Firmennamen auch Meldungen über Produkte anderer Unternehmen zurückgibt, die den Namen nur nebenbei erwähnen. Diese Seite lässt sie weg. 0 Registereinträge nennen Juniper Networks, ohne eines seiner Produkte als betroffen zu benennen. Ein Spiegel, der sie mitführt, erzeugt eine längere Seite und eine falsche Zahl.
Woher stammen die Meldungen zu Juniper Networks auf dieser Seite?
Aus diesen Registern: European Vulnerability Database, betrieben von ENISA, Europäische Union; CERT-Bund Sicherheitshinweise, betrieben von BSI, Bundesrepublik Deutschland; Katalog bekannt ausgenutzter Schwachstellen, betrieben von CISA, Vereinigte Staaten. Jeder Eintrag verlinkt zurück auf das Register, das ihn veröffentlicht hat, und trägt das Datum, das dieses Register nennt. Führen mehrere Register dieselbe Schwachstelle, steht sie einmal da, mit einem Link auf jedes, statt doppelt gezählt zu werden.
Heißt eine lange Liste, dass Juniper Networks unsicher ist?
Nein. Ein Register hält fest, was Forschende gefunden und was der Anbieter offengelegt hat. Ein weit verbreitetes Produkt mit einem funktionierenden Offenlegungsprozess sammelt deshalb mehr Einträge als eines, das niemand prüft. Eine kurze Liste kann genauso gut für eine kleine Installationsbasis stehen oder für einen Anbieter, der wenig veröffentlicht. Diese Seite gibt den Bestand wieder und bewertet den Anbieter nicht, denn ob das für Sie tragbar ist, hängt an Ihrer Risikobereitschaft, Ihrem Compliance-Umfang und den Alternativen, die Sie abwägen.
Eine Liste von Meldungen ist noch keine Risikobewertung
Es zählt, welche davon die Komponenten betreffen, die Sie tatsächlich betreiben, in der Konfiguration, in der Sie sie betreiben, und ob das neben den Alternativen Ihrer engeren Auswahl tragbar ist. DecisionOS liest denselben Bestand an den Kriterien einer konkreten Entscheidung und liefert ein Memo, das vor Geschäftsführung und Revision standhält.
Der vollständige Bestand zu Juniper Networks, samt Quellen und offenen Fragen
