← Back

CVE-2018-0004

nvd nist
Published: Jan 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the device. This affects one or more threads and conversely one or more running processes running on the system. Once this occurs, the high CPU event(s) affects either or both the forwarding and control plane. As a result of this condition the device can become inaccessible in either or both the control and forwarding plane and stops forwarding traffic until the device is rebooted. The issue will reoccur after reboot upon receiving further transit traffic. Score: 5.7 MEDIUM (CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) For network designs utilizing layer 3 forwarding agents or other ARP through layer 3 technologies, the score is slightly higher. Score: 6.5 MEDIUM (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) If the following entry exists in the RE message logs then this may indicate the issue is present. This entry may or may not appear when this issue occurs. /kernel: Expensive timeout(9) function: Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D50; 12.3X48 versions prior to 12.3X48-D30; 12.3R versions prior to 12.3R12-S7; 14.1 versions prior to 14.1R8-S4, 14.1R9; 14.1X53 versions prior to 14.1X53-D30, 14.1X53-D34; 14.2 versions prior to 14.2R8; 15.1 versions prior to 15.1F6, 15.1R3; 15.1X49 versions prior to 15.1X49-D40; 15.1X53 versions prior to 15.1X53-D31, 15.1X53-D33, 15.1X53-D60. No other Juniper Networks products or platforms are affected by this issue.

Affected (76)

Products: Juniper: Junos
1 product
Junos
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 12.1x46
Version 12.1x46 d10
Version 12.1x46 d15
Version 12.1x46 d20
Version 12.1x46 d25
Version 12.1x46 d30
Version 12.1x46 d35
Version 12.1x46 d40
Version 12.1x46 d45
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 12.3x48
Version 12.3x48 d10
Version 12.3x48 d15
Version 12.3x48 d20
Version 12.3x48 d25
Configuration C
11 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 12.3 r11
Version 12.3 r12
Version 12.3 r1
Version 12.3 r2
Version 12.3 r3
Version 12.3 r4
Version 12.3 r5
Version 12.3 r6
Version 12.3 r7
Version 12.3 r8
Version 12.3 r9
Configuration D
9 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.1
Version 14.1 r1
Version 14.1 r2
Version 14.1 r3
Version 14.1 r4
Version 14.1 r5
Version 14.1 r6
Version 14.1 r7
Version 14.1 r9
Configuration E
8 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.1x53
Version 14.1x53 d10
Version 14.1x53 d15
Version 14.1x53 d16
Version 14.1x53 d25
Version 14.1x53 d26
Version 14.1x53 d27
Version 14.1x53 d34
Configuration F
8 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 14.2
Version 14.2 r1
Version 14.2 r2
Version 14.2 r3
Version 14.2 r4
Version 14.2 r5
Version 14.2 r6
Version 14.2 r7
Configuration G
12 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1
Version 15.1 a1
Version 15.1 f1
Version 15.1 f2-s1
Version 15.1 f2-s2
Version 15.1 f2-s3
Version 15.1 f2-s4
Version 15.1 f2
Version 15.1 f3
Version 15.1 f4
Version 15.1 f5
Version 15.1 r3
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1x49
Version 15.1x49 d10
Version 15.1x49 d20
Version 15.1x49 d30
Version 15.1x49 d35
Configuration I
9 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1x53
Version 15.1x53 d10
Version 15.1x53 d20
Version 15.1x53 d210
Version 15.1x53 d21
Version 15.1x53 d25
Version 15.1x53 d30
Version 15.1x53 d33
Version 15.1x53 d60

References (4)

Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.