Qfx5100
Vendor:
First CVE: Jul 16, 2015 · Active for 11 years
49
Total CVEs
More Total CVEs than 98% of tracked products
4.9
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Qfx5100 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2015
11 years ago
Most Recent CVE
Jan 12, 2024
925 days ago
CVE Severity & Scoring
Qfx510049 CVEs
57%
39%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.0%)
Network29 (59.2%)
Unknown1 (2.0%)
Physical2 (4.1%)
Adjacent Network16 (32.7%)
Attack Complexity
Low40 (81.6%)
High8 (16.3%)
Unknown1 (2.0%)
User Interaction
None47 (95.9%)
Unknown1 (2.0%)
Required1 (2.0%)
Privileges Required
Low1 (2.0%)
High2 (4.1%)
None45 (91.8%)
Unknown1 (2.0%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0006CRITICAL A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devi | Jan 15, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-0008CRITICAL A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4 | Apr 10, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-0043HIGH Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending specific MP | Oct 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-0005HIGH QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or | Jan 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-0014HIGH On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all interfaces to go down. By continuo | Jan 15, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-22188HIGH An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based un | Apr 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-0207HIGH An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through | Jan 15, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-0049HIGH A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of this specifically crafted malic | Oct 10, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-22174HIGH A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a pack | Jan 19, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-0285HIGH An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate | Jul 15, 2021 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Qfx5100
Top CWEs
Versions
No cataloged versions.