CVE-2019-0061
- EPSS 0.04%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:09
The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due ...
CVE-2019-0062
- EPSS 0.36%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device. This issue affects: Junipe...
CVE-2019-0063
- EPSS 0.21%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 enabled, jdhcpd might crash when receiving a specific crafted DHCP response message on a subscriber interface. The daemon automatic...
CVE-2019-0064
- EPSS 0.39%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
On SRX5000 Series devices, if 'set security zones security-zone <zone> tcp-rst' is configured, the flowd process may crash when a specific TCP packet is received by the device and triggers a new session. The process restarts automatically. However, r...
CVE-2019-0065
- EPSS 0.28%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
On MX Series, when the SIP ALG is enabled, receipt of a certain malformed SIP packet may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sending a crafted SIP packet, an attacker can repeatedly bring down MS-PIC on MS-MIC/MS-MPC causi...
CVE-2019-0066
- EPSS 0.47%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of Juniper Networks Junos OS allows attacker to cause a Denial of Service (DoS) condition and core the routing protocol daemon (rpd) process when a spec...
CVE-2019-0067
- EPSS 0.08%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
Receipt of a specific link-local IPv6 packet destined to the RE may cause the system to crash and restart (vmcore). By continuously sending a specially crafted IPv6 packet, an attacker can repeatedly crash the system causing a prolonged Denial of Ser...
CVE-2019-0068
- EPSS 0.28%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:10
The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packets. By continuously sending the specific multicast packets, an attacker can repeatedly crash the flowd process causing a sustained...
CVE-2019-0069
- EPSS 0.02%
- Published 09.10.2019 20:15:17
- Last modified 21.11.2024 04:16:11
On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SRX1500, SRX4000 Series, vSRX, SRX1500, SRX4000, QFX5110, QFX5200, QFX10K Series, when the user uses console management port to auth...
CVE-2019-0047
- EPSS 0.65%
- Published 09.10.2019 20:15:16
- Last modified 21.11.2024 04:16:07
A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos administrator to first perfor...