Nfx350
Vendor:
First CVE: Oct 16, 2020 · Active for 5 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nfx350 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2020
5 years ago
Most Recent CVE
Jul 11, 2024
743 days ago
CVE Severity & Scoring
Nfx35011 CVEs
36%
55%
9%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (36.4%)
Network5 (45.5%)
Unknown0 (0.0%)
Physical1 (9.1%)
Adjacent Network1 (9.1%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-0248CRITICAL This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any insta | Apr 22, 2021 | 10.0 | 32 | NO | NO |
CVE-2024-21586HIGH An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unau | Jul 1, 2024 | 7.5 | 25 | NO | NO |
CVE-2021-0253HIGH NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos | Apr 22, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-0252HIGH NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos De | Apr 22, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-0207HIGH An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through | Jan 15, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-39545HIGH An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series with SPC3 and NFX350 allows | Jul 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-28972MEDIUM An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. | Apr 17, 2023 | 6.8 | 22 | NO | NO |
CVE-2021-0289MEDIUM When user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) interface units, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability b | Jul 15, 2021 | 5.3 | 20 | NO | NO |
CVE-2021-0206HIGH A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, | Jan 15, 2021 | 7.5 | 19 | NO | NO |
CVE-2020-1688MEDIUM On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted comm | Oct 16, 2020 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Nfx350
Top CWEs
Versions
No cataloged versions.