
CVE-2016-1261 – Junos: vulnerabilities in J-Web (CVE-2016-1261)
https://notcve.org/view.php?id=CVE-2016-1261
13 Oct 2017 — J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS). J-Web no valida ciertas entradas que pueden pueden provocar problemas de Cross-Site Request Forgery (CSRF) o una denegación del servicio J-Web (DoS). • https://kb.juniper.net/JSA10723 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-10608 – SRX series: Junos OS: SRX series using IPv6 Sun/MS-RPC ALGs may experience flowd crash on processing packets.
https://notcve.org/view.php?id=CVE-2017-10608
13 Oct 2017 — Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated denial of service against the target. Repeated traffic in a cluster may cause repeated flip-flop failure operations or full failure to the flowd daemon halting traffic on all nodes. Only IPv6 traffic is affected by this issue. IPv4 traffic is unaffected... • https://kb.juniper.net/JSA10811 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-10618 – Junos: RPD core due to BGP UPDATE with malformed optional transitive attributes
https://notcve.org/view.php?id=CVE-2017-10618
13 Oct 2017 — When the 'bgp-error-tolerance' feature â" designed to help mitigate remote session resets from malformed path attributes â" is enabled, a BGP UPDATE containing a specifically crafted set of transitive attributes can cause the RPD routing process to crash and restart. Devices with BGP enabled that do not have 'bgp-error-tolerance' configured are not vulnerable to this issue. Affected releases are Juniper Networks Junos OS 13.3 prior to 13.3R10-S2; 14.1 prior to 14.1R8-S4, 14.1R9; 14.1X5... • https://kb.juniper.net/JSA10820 •

CVE-2017-10613 – Junos OS: A kernel hang may occur due to a specific loopback filter action command
https://notcve.org/view.php?id=CVE-2017-10613
13 Oct 2017 — A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a running configuration of Juniper Networks Junos OS, allows an attacker with CLI access and the ability to initiate remote sessions to the loopback interface with the defined action, to hang the kernel. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D55; 12.3X48 prior to 12.3X48-D35; 14.1 prior to 14.1R8-S4, 14.1R9; 14.1X53 prior to 14.1X53-D40; 14.2 prior to 14.2R4... • https://kb.juniper.net/JSA10816 • CWE-400: Uncontrolled Resource Consumption •

CVE-2016-4922 – Junos: Privilege escalation vulnerabilities in Junos CLI
https://notcve.org/view.php?id=CVE-2016-4922
13 Oct 2017 — Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevated privileges and gain complete control of the device. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.1X46 prior to 12.1X46-D60; 12.1X47 prior to 12.1X47-D45; 12.3 prior to 12.3R12; 12.3X48 prior to 12.3X48-D35; 13.2 prior ... • http://www.securityfocus.com/bid/93534 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2016-4923 – Junos J-Web: Cross Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2016-4923
13 Oct 2017 — Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data and credentials from a J-Web session and to perform administrative actions on the Junos device. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.1X44 prior to 12.1X44-D60; 12.1X46 prior to 12.1X46-D40; 12.1... • http://www.securityfocus.com/bid/93529 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-10621 – Junos OS: Denial of service vulnerability in telnetd
https://notcve.org/view.php?id=CVE-2017-10621
13 Oct 2017 — A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9; 14.1X53 prior to 14.1X53-D50; 14.2 prior to 14.2R7-S9, 14.2R8; 15.1 prior to 15.1F2-S16, 15.1F5-S7, 15.1F6-S6, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D90; 15.1X53 prior to 15.1X53-D47; 16.1 prior to 16.1R4-S1, 16.1R5; 16.2 prior t... • https://kb.juniper.net/JSA10817 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-10605 – Junos: SRX Series denial of service vulnerability in flowd due to crafted DHCP packet
https://notcve.org/view.php?id=CVE-2017-10605
14 Jul 2017 — On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended denial of service condition for the device(s). If the device is configured in high-availability, the RG1+ (data-plane) will fail-over to the secondary node. If the device is configured in stand-alone, there will be temporary traffic in... • http://www.securitytracker.com/id/1038891 • CWE-20: Improper Input Validation •

CVE-2017-2345 – Junos: snmpd denial of service upon receipt of crafted SNMP packet
https://notcve.org/view.php?id=CVE-2017-2345
14 Jul 2017 — On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and restart by sending a crafted SNMP packet. Repeated crashes of the snmpd daemon can result in a partial denial of service condition. Additionally, it may be possible to craft a malicious SNMP packet in a way that can result in remote code execution. SNMP is disabled in Junos OS by default. Junos OS devices with SNMP disabled are not affected by this issue. • http://www.securityfocus.com/bid/99567 • CWE-20: Improper Input Validation •

CVE-2017-2344 – Junos: Buffer overflow in sockets library
https://notcve.org/view.php?id=CVE-2017-2344
14 Jul 2017 — A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow. Malicious exploitation of this issue may lead to a denial of service (kernel panic) or be leveraged as a privilege escalation through local code execution. The routines are only accessible via programs running on the device itself, and veriexec restricts arbitrary programs from running on Junos OS. There are no known exploit vectors utilizing signed binaries shipped with Junos OS itself. Affected releases are Juniper N... • http://www.securityfocus.com/bid/99556 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •