← Back

CVE-2018-0009

nvd nist
Published: Jan 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

On Juniper Networks SRX series devices, firewall rules configured to match custom application UUIDs starting with zeros can match all TCP traffic. Due to this issue, traffic that should have been blocked by other rules is permitted to flow through the device resulting in a firewall bypass condition. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71 on SRX series; 12.3X48 versions prior to 12.3X48-D55 on SRX series; 15.1X49 versions prior to 15.1X49-D100 on SRX series.

Affected (40)

Products: Juniper: Junos
1 product
Junos
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 12.1x46
Version 12.1x46 d10
Version 12.1x46 d15
Version 12.1x46 d20
Version 12.1x46 d25
Version 12.1x46 d30
Version 12.1x46 d35
Version 12.1x46 d40
Version 12.1x46 d45
Version 12.1x46 d50
Version 12.1x46 d55
Version 12.1x46 d60
Version 12.1x46 d65
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 12.3x48
Version 12.3x48 d10
Version 12.3x48 d15
Version 12.3x48 d20
Version 12.3x48 d25
Version 12.3x48 d30
Version 12.3x48 d35
Version 12.3x48 d40
Version 12.3x48 d45
Version 12.3x48 d50
Version 12.3x48 d55
Configuration C
16 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1x49
Version 15.1x49 d100
Version 15.1x49 d10
Version 15.1x49 d20
Version 15.1x49 d30
Version 15.1x49 d35
Version 15.1x49 d40
Version 15.1x49 d45
Version 15.1x49 d50
Version 15.1x49 d55
Version 15.1x49 d60
Version 15.1x49 d65
Version 15.1x49 d70
Version 15.1x49 d75
Version 15.1x49 d80
Version 15.1x49 d90
Running on/withPlatform Versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx1500
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx240
All versions
Juniper
Srx300
All versions
Juniper
Srx320
All versions
Juniper
Srx340
All versions
Juniper
Srx3400
All versions
Juniper
Srx345
All versions
Juniper
Srx3600
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx5400
All versions
Juniper
Srx550
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions

References (6)

Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory

Timeline

No history available yet.