← Back

CVE-2017-10619

nvd nist
Published: Oct 13, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

When Express Path (formerly known as service offloading) is configured on Juniper Networks SRX1400, SRX3400, SRX3600, SRX5400, SRX5600, SRX5800 in high availability cluster configuration mode, certain multicast packets might cause the flowd process to crash, halting or interrupting traffic from flowing through the device and triggering RG1+ (data-plane) fail-over to the secondary node. Repeated crashes of the flowd process may constitute an extended denial of service condition. This service is not enabled by default and is only supported in high-end SRX platforms. Affected releases are Juniper Networks Junos OS 12.3X48 prior to 12.3X48-D45, 15.1X49 prior to 15.1X49-D80 on SRX1400, SRX3400, SRX3600, SRX5400, SRX5600, SRX5800.

Affected (2)

Products: Juniper: Junos
1 product
Junos
Configuration A
2 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 12.3x48
Version 15.1x49
Running on/withPlatform Versions
Juniper
Srx1400
All versions
Juniper
Srx3400
All versions
Juniper
Srx3600
All versions
Juniper
Srx5400
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.