Juniper
Junos OS
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This CVE identity is linked to the Lifecycle record Juniper Junos OS. Use that record for publisher support phases and retirement dates.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2025-21590 | 12 Mar 2025 | Junos OS: < 21.2R3-S9, 21.4 < 21.4R3-S10, 22.2 < 22.2R3-S6, 22.4 < 22.4R3-S6, 23.2 < 23.2R2-S3, 23.4 < 23.4R2-S4, 24.2 < 24.2R1-S2, 24.2R2 | The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.; Please note that this issue is not fixed for all platforms in the releases specified in the solution section.; For the following products the fix is only available in these releases:; SRX300 Series 21.2R3-S9, 23.4R2-S5*, 24.4R1; SRX550HM 22.2R3-S7*; EX4300 Series 21.4R3-S11* (except EX4300-48MP which has fixes available as indicated in the solution); EX4600 21.4R3-S11* (except EX4650 which has fixes available as indicated in the solution); ACX1000, ACX1100, ACX2100, ACX2200, ACX4000,; ACX500 21.2R3-S9; MX104 21.2R3-S9; * Future Release | Update reference ↗ |
| CVE-2023-36851 | 26 Sep 2023 | Junos OS: 21.2 < 21.2R3-S8, 21.4 < 21.4R3-S6, 22.1 < 22.1R3-S5, 22.2 < 22.2R3-S3, 22.3 < 22.3R3-S2, 22.4 < 22.4R2-S2, 22.4R3, 23.2 < 23.2R1-S2, 23.2R2 | The following software releases have been updated to resolve this specific issue: 21.2R3-S8*, 21.4R3-S6*, 22.1R3-S5*, 22.2R3-S3*, 22.3R3-S2*, 22.4R2-S2, 22.4R3*, 23.2R1-S2, 23.2R2*, 23.4R1, and all subsequent releases.; *Pending Publication | Update reference ↗ |
| CVE-2023-36846 | 17 Aug 2023 | Junos OS: < 20.4R3-S8, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S3, 22.2 < 22.2R3-S2, 22.3 < 22.3R2-S2, 22.3R3, 22.4 < 22.4R2-S1, 22.4R3 | The following software releases have been updated to resolve this specific issue:; 20.4R3-S8, 21.2R3-S6, 21.3R3-S5*, 21.4R3-S5*, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3*, 23.2R1, and all subsequent releases.; *Pending Publication | Update reference ↗ |
| CVE-2023-36845 | 17 Aug 2023 | Junos OS: < 20.4R3-S9, 21.1 < 21.1*, 21.2 < 21.2R3-S7, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S4, 22.2 < 22.2R3-S2, 22.3 < 22.3R2-S2, 22.3R3-S1, 22.4 < 22.4R2-S1, 22.4R3, 23,2 < 23.2R1-S1, 23.2R2 | The following software releases have been updated to resolve this specific issue:; 20.4R3-S9*, 21.2R3-S7*, 21.3R3-S5, 21.4R3-S5*, 22.1R3-S4*, 22.2R3-S2, 22.3R2-S2, 22.3R3-S1*, 22.4R2-S1, 22.4R3*, 23.2R1-S1, 23.2R2*, 23.4R1*, and all subsequent releases.; *Pending Publication | Update reference ↗ |
| CVE-2023-36844 | 17 Aug 2023 | Junos OS: < 20.4R3-S9, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S4, 22.2 < 22.2R3-S2, 22.3 < 22.3R3-S1, 22.4 < 22.4R2-S2, 22.4R3, 23.2 < 23.2R1-S1, 23.2R2 | The following software releases have been updated to resolve this specific issue:; 20.4R3-S9*, 21.2R3-S7*, 21.3R3-S5*, 21.4R3-S5*, 22.1R3-S4*, 22.2R3-S2, 22.3R3-S1*, 22.4R2-S2*, 22.4R3*, 23.2R1-S1, 23.2R2*, 23.4R1*, and all subsequent releases.; *Pending Publication | Update reference ↗ |
| CVE-2023-36847 | 17 Aug 2023 | Junos OS: < 20.4R3-S8, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S4, 22.1 < 22.1R3-S3, 22.2 < 22.2R3-S1, 22.3 < 22.3R2-S2, 22.3R3, 22.4 < 22.4R2-S1, 22.4R3 | The following software releases have been updated to resolve this specific issue:; 20.4R3-S8, 21.2R3-S6, 21.3R3-S5*, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3*, 23.2R1, and all subsequent releases.; *Pending Publication | Update reference ↗ |
| CVE-2020-1631 | 4 May 2020 | Junos OS: 12.3 < 12.3R12-S16, 12.3X48 < 12.3X48-D101, 12.3X48-D105, 14.1X53 < 14.1X53-D54, 15.1 < 15.1R7-S7, 15.1X49 < 15.1X49-D211, 15.1X49-D220, 16.1 < 16.1R7-S8, 17.2 < 17.2R3-S4, 17.3 < 17.3R3-S8, 17.4 < 17.4R2-S11, 17.4R3-S2, 18.1 < 18.1R3-S10, 18.2 < 18.2R2-S7, 18.2R3-S4, 18.3 < 18.3R2-S4, 18.3R3-S2, 18.4 < 18.4R1-S7, 18.4R3-S2, 19.1 < 19.1R1-S5, 19.1R3-S1, 19.2 < 19.2R2, 19.3 < 19.3R2-S3, 19.3R3, 19.4 < 19.4R1-S2, 19.4R2, 20.1 < 20.1R1-S1, 20.1R2 | The following software releases have been updated to resolve this specific issue: 12.3R12-S16, 12.3X48-D101, 12.3X48-D105, 14.1X53-D54, 15.1X49-D211, 15.1X49-D220, 15.1R7-S7, 16.1R7-S8, 17.2R3-S4, 17.4R2-S11, 17.3R3-S8, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S4, 18.3R2-S4, 18.3R3-S2, 18.4R1-S7, 18.4R3-S2, 19.1R1-S5, 19.1R3-S1, 19.2R2, 19.3R2-S3, 19.3R3, 19.4R1-S2, 19.4R2, 20.1R1-S1, 20.1R2 and all subsequent releases.; Note: At the time of this publication, the following fixed releases are available for customer download: 12.3X48-D101, 15.1X49-D211, 18.2R3-S4, 18.4R3-S2, and 20.1R1-S1, the remaining fixed releases will be available in future time.; 12.3X48-D101 & 15.1X49-D211 releases can be downloaded from the below URLs:; 12.3X48-D101 :; Branch SRX-Series Install Package (for SRX100H2, SRX110HE2, SRX210H2, SRX220H2, SRX240H2, SRX550, SRX650): junos-srxsme-12.3X48-D101-domestic.tgz; https://webdownload.juniper.net/swdl/dl/secure/site/1/record/107438.html; MD5 = b822376f7a385e74499b186cf28c122b; SHA-1 = e6138e45bf9d29e962468e6e114e537142d4cc0d; SHA-256 = b21a9ae9f5d0b0ec25180682193faba7bf54e836fda0eb78babd3df843f90e6a; SRX 1000/3000-Series Install Package : junos-srx1k3k-12.3X48-D101-domestic.tgz; https://webdownload.juniper.net/swdl/dl/secure/site/1/record/107436.html; MD5 = b93229ea43f66b539f22ecc5a9be0f07 | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.