QFX5100-24Q-AA-AFO
Announced in: QFX5100 24Q AA AFI AFO and QFX PFA 4Q
Chassis
· QFX Series
Is the QFX5100-24Q-AA-AFO still supported?
No. Juniper ended support for the QFX5100 24Q AA AFI AFO and QFX PFA 4Q on 2025-08-31. No further security fixes will be issued. See Juniper's lifecycle bulletin.
When does the QFX5100-24Q-AA-AFO reach end of support?
Juniper support for the QFX5100 24Q AA AFI AFO and QFX PFA 4Q ends on 2025-08-31.
What replaces the QFX5100-24Q-AA-AFO?
Juniper has not published a successor model for the QFX5100 24Q AA AFI AFO and QFX PFA 4Q.
What known-exploited CVEs apply to the QFX5100-24Q-AA-AFO past end of support?
7 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the QFX5100 24Q AA AFI AFO and QFX PFA 4Q runs. These will not be patched on this device because it is past the Juniper security-support date. See the Known Exploited Vulnerabilities table below for the full list.
Known Exploited Vulnerabilities
This device is past Juniper's security-support date. 7 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Juniper is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2025-21590
|
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | ||
CVE-2023-36844
|
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability | ||
CVE-2023-36845
|
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | ||
CVE-2023-36846
|
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | ||
CVE-2023-36847
|
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | ||
CVE-2023-36851
|
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | ||
CVE-2020-1631
|
Juniper Junos OS Path Traversal Vulnerability |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
QFX5100-24Q-AA-AFO Lifecycle Overview
The Juniper QFX5100-24Q-AA-AFO (QFX5100-24Q-AA-AFO) is a chassis product in the Juniper QFX series. This product has reached end of life as of , meaning Juniper no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the QFX5100-24Q-AA-AFO should plan a migration .
Lifecycle Milestones
| Lifecycle notice published | 5y 9mo ago | |
|---|---|---|
| End of sale | 5y 9mo ago | |
| Last date of support | 9mo ago |
Additional Dates
| Last Warranty Conversion Date | 4y 9mo ago | |
|---|---|---|
| Same Day Support Discontinued Date | 9mo ago | |
| Next Day Support Discontinued Date | 9mo ago |