Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY7 SECURITY RECORDS

Juniper

Junos OS

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Juniper Junos OS. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2025-21590 12 Mar 2025 Junos OS: < 21.2R3-S9, 21.4 < 21.4R3-S10, 22.2 < 22.2R3-S6, 22.4 < 22.4R3-S6, 23.2 < 23.2R2-S3, 23.4 < 23.4R2-S4, 24.2 < 24.2R1-S2, 24.2R2 The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.; Please note that this issue is not fixed for all platforms in the releases specified in the solution section.; For the following products the fix is only available in these releases:; SRX300 Series 21.2R3-S9, 23.4R2-S5*, 24.4R1; SRX550HM 22.2R3-S7*; EX4300 Series 21.4R3-S11* (except EX4300-48MP which has fixes available as indicated in the solution); EX4600 21.4R3-S11* (except EX4650 which has fixes available as indicated in the solution); ACX1000, ACX1100, ACX2100, ACX2200, ACX4000,; ACX500 21.2R3-S9; MX104 21.2R3-S9; * Future Release Update reference ↗
CVE-2023-36851 26 Sep 2023 Junos OS: 21.2 < 21.2R3-S8, 21.4 < 21.4R3-S6, 22.1 < 22.1R3-S5, 22.2 < 22.2R3-S3, 22.3 < 22.3R3-S2, 22.4 < 22.4R2-S2, 22.4R3, 23.2 < 23.2R1-S2, 23.2R2 The following software releases have been updated to resolve this specific issue: 21.2R3-S8*, 21.4R3-S6*, 22.1R3-S5*, 22.2R3-S3*, 22.3R3-S2*, 22.4R2-S2, 22.4R3*, 23.2R1-S2, 23.2R2*, 23.4R1, and all subsequent releases.; *Pending Publication Update reference ↗
CVE-2023-36846 17 Aug 2023 Junos OS: < 20.4R3-S8, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S3, 22.2 < 22.2R3-S2, 22.3 < 22.3R2-S2, 22.3R3, 22.4 < 22.4R2-S1, 22.4R3 The following software releases have been updated to resolve this specific issue:; 20.4R3-S8, 21.2R3-S6, 21.3R3-S5*, 21.4R3-S5*, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3*, 23.2R1, and all subsequent releases.; *Pending Publication Update reference ↗
CVE-2023-36845 17 Aug 2023 Junos OS: < 20.4R3-S9, 21.1 < 21.1*, 21.2 < 21.2R3-S7, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S4, 22.2 < 22.2R3-S2, 22.3 < 22.3R2-S2, 22.3R3-S1, 22.4 < 22.4R2-S1, 22.4R3, 23,2 < 23.2R1-S1, 23.2R2 The following software releases have been updated to resolve this specific issue:; 20.4R3-S9*, 21.2R3-S7*, 21.3R3-S5, 21.4R3-S5*, 22.1R3-S4*, 22.2R3-S2, 22.3R2-S2, 22.3R3-S1*, 22.4R2-S1, 22.4R3*, 23.2R1-S1, 23.2R2*, 23.4R1*, and all subsequent releases.; *Pending Publication Update reference ↗
CVE-2023-36844 17 Aug 2023 Junos OS: < 20.4R3-S9, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S5, 22.1 < 22.1R3-S4, 22.2 < 22.2R3-S2, 22.3 < 22.3R3-S1, 22.4 < 22.4R2-S2, 22.4R3, 23.2 < 23.2R1-S1, 23.2R2 The following software releases have been updated to resolve this specific issue:; 20.4R3-S9*, 21.2R3-S7*, 21.3R3-S5*, 21.4R3-S5*, 22.1R3-S4*, 22.2R3-S2, 22.3R3-S1*, 22.4R2-S2*, 22.4R3*, 23.2R1-S1, 23.2R2*, 23.4R1*, and all subsequent releases.; *Pending Publication Update reference ↗
CVE-2023-36847 17 Aug 2023 Junos OS: < 20.4R3-S8, 21.1 < 21.1*, 21.2 < 21.2R3-S6, 21.3 < 21.3R3-S5, 21.4 < 21.4R3-S4, 22.1 < 22.1R3-S3, 22.2 < 22.2R3-S1, 22.3 < 22.3R2-S2, 22.3R3, 22.4 < 22.4R2-S1, 22.4R3 The following software releases have been updated to resolve this specific issue:; 20.4R3-S8, 21.2R3-S6, 21.3R3-S5*, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3*, 23.2R1, and all subsequent releases.; *Pending Publication Update reference ↗
CVE-2020-1631 4 May 2020 Junos OS: 12.3 < 12.3R12-S16, 12.3X48 < 12.3X48-D101, 12.3X48-D105, 14.1X53 < 14.1X53-D54, 15.1 < 15.1R7-S7, 15.1X49 < 15.1X49-D211, 15.1X49-D220, 16.1 < 16.1R7-S8, 17.2 < 17.2R3-S4, 17.3 < 17.3R3-S8, 17.4 < 17.4R2-S11, 17.4R3-S2, 18.1 < 18.1R3-S10, 18.2 < 18.2R2-S7, 18.2R3-S4, 18.3 < 18.3R2-S4, 18.3R3-S2, 18.4 < 18.4R1-S7, 18.4R3-S2, 19.1 < 19.1R1-S5, 19.1R3-S1, 19.2 < 19.2R2, 19.3 < 19.3R2-S3, 19.3R3, 19.4 < 19.4R1-S2, 19.4R2, 20.1 < 20.1R1-S1, 20.1R2 The following software releases have been updated to resolve this specific issue: 12.3R12-S16, 12.3X48-D101, 12.3X48-D105, 14.1X53-D54, 15.1X49-D211, 15.1X49-D220, 15.1R7-S7, 16.1R7-S8, 17.2R3-S4, 17.4R2-S11, 17.3R3-S8, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S4, 18.3R2-S4, 18.3R3-S2, 18.4R1-S7, 18.4R3-S2, 19.1R1-S5, 19.1R3-S1, 19.2R2, 19.3R2-S3, 19.3R3, 19.4R1-S2, 19.4R2, 20.1R1-S1, 20.1R2 and all subsequent releases.; Note: At the time of this publication, the following fixed releases are available for customer download: 12.3X48-D101, 15.1X49-D211, 18.2R3-S4, 18.4R3-S2, and 20.1R1-S1, the remaining fixed releases will be available in future time.; 12.3X48-D101 & 15.1X49-D211 releases can be downloaded from the below URLs:; 12.3X48-D101 :; Branch SRX-Series Install Package (for SRX100H2, SRX110HE2, SRX210H2, SRX220H2, SRX240H2, SRX550, SRX650): junos-srxsme-12.3X48-D101-domestic.tgz; https://webdownload.juniper.net/swdl/dl/secure/site/1/record/107438.html; MD5 = b822376f7a385e74499b186cf28c122b; SHA-1 = e6138e45bf9d29e962468e6e114e537142d4cc0d; SHA-256 = b21a9ae9f5d0b0ec25180682193faba7bf54e836fda0eb78babd3df843f90e6a; SRX 1000/3000-Series Install Package : junos-srx1k3k-12.3X48-D101-domestic.tgz; https://webdownload.juniper.net/swdl/dl/secure/site/1/record/107436.html; MD5 = b93229ea43f66b539f22ecc5a9be0f07 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.