← Back

CVE-2017-10611

nvd nist
Published: Oct 13, 2017Modified: May 13, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE processing can result in an extended denial of service condition. This issue only affects the following platforms: (1) EX2200, EX3300, XRE200 (2) MX Series routers with MPC7E/8E/9E PFEs installed, and only if 'extended-statistics' are enabled under the [edit chassis] configuration. Affected releases are Juniper Networks Junos OS 14.1 prior to 14.1R8-S5, 14.1R9 on MX Series; 14.1X53 prior to 14.1X53-D46, 14.1X53-D50 on EX2200, EX3300, XRE200; 14.2 prior to 14.2R7-S9, 14.2R8 on MX Series; 15.1 prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S3, 15.1R6 on MX Series; 16.1 prior to 16.1R4-S5, 16.1R5, 16.1R6 on MX Series; 16.1X65 prior to 16.1X65-D45 on EX2200, EX3300, XRE200; 16.2 prior to 16.2R2-S1, 16.2R3 on MX Series; 17.1 prior to 17.1R2-S2, 17.1R3 on MX Series; 17.2 prior to 17.2R1-S3, 17.2R2 on MX Series; 17.2X75 prior to 17.2X75-D50 on MX Series; 17.3 prior to 17.3R1-S1, 17.3R2 on MX Series. No other Juniper Networks products or platforms are affected by this issue.

Affected (71)

Products: Juniper: Junos
1 product
Junos
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.1
Version 14.1 r1
Version 14.1 r2
Version 14.1 r3
Version 14.1 r4
Version 14.1 r5
Version 14.1 r6
Version 14.1 r7
Version 14.1 r8
Version 14.1 r9
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.1x53
Version 14.1x53 d10
Version 14.1x53 d15
Version 14.1x53 d16
Version 14.1x53 d25
Version 14.1x53 d26
Version 14.1x53 d27
Version 14.1x53 d30
Version 14.1x53 d35
Version 14.1x53 d40
Version 14.1x53 d45
Version 14.1x53 d50
Configuration C
9 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.2
Version 14.2 r1
Version 14.2 r2
Version 14.2 r3
Version 14.2 r4
Version 14.2 r5
Version 14.2 r6
Version 14.2 r7
Version 14.2 r8
Configuration D
17 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1 f1
Version 15.1 f2-s1
Version 15.1 f2-s2
Version 15.1 f2-s3
Version 15.1 f2-s4
Version 15.1 f2
Version 15.1 f3
Version 15.1 f4
Version 15.1 f5
Version 15.1 f6-s8
Version 15.1 r1
Version 15.1 r2
Version 15.1 r3
Version 15.1 r4
Version 15.1 r5-s3
Version 15.1 r5
Version 15.1 r6
Configuration E
6 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 16.1 r1
Version 16.1 r2
Version 16.1 r3
Version 16.1 r4
Version 16.1 r5
Version 16.1 r6
Configuration F
4 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 16.1x65
Version 16.1x65 d30
Version 16.1x65 d35
Version 16.1x65 d40
Running on/withPlatform Versions
Juniper
Ex2200
All versions
Juniper
Ex3300
All versions
Juniper
Xre200
All versions
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 16.2
Version 16.2 r1
Version 16.2 r2
Version 16.2 r3
Configuration H
4 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.1
Version 17.1 r1
Version 17.1 r2
Version 17.1 r3
Configuration I
3 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.2
Version 17.2 r1
Version 17.2 r2
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 17.2x75
Configuration K
1 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Version 17.3 r1
Running on/withPlatform Versions
Juniper
Mx10
All versions
Juniper
Mx104
All versions
Juniper
Mx2010
All versions
Juniper
Mx2020
All versions
Juniper
Mx240
All versions
Juniper
Mx40
All versions
Juniper
Mx480
All versions
Juniper
Mx5
All versions
Juniper
Mx80
All versions
Juniper
Mx960
All versions
Juniper
Vmx
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.