CVE-2020-1631: Juniper Junos OS
EPSS4.8%No. 1424 of 1739 in KEV
CVE year2020~2 yrs before listing
Same vendor in KEV8
Same product7
| Field | Value |
|---|---|
| Vendor | Juniper |
| Product | Junos OS |
| Name | Juniper Junos OS Path Traversal Vulnerability |
| Added to KEV | 2022-03-25 |
| US federal due date | 2022-04-15 |
| Ransomware use | Unknown |
| CWE | CWE-22, CWE-73 |
CISA description
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2025-21590 | Juniper Junos OS | 2025-03-13 | 1.7% | Unknown |
| CVE-2023-36851 | Juniper Junos OS | 2023-11-13 | 1.1% | Unknown |
| CVE-2023-36847 | Juniper Junos OS | 2023-11-13 | 83.4% | Unknown |
| CVE-2023-36846 | Juniper Junos OS | 2023-11-13 | 93.4% | Unknown |
| CVE-2023-36845 | Juniper Junos OS | 2023-11-13 | 95.0% | Unknown |
| CVE-2023-36844 | Juniper Junos OS | 2023-11-13 | 89.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Juniper Junos OS vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25.