← Back

CVE-2018-0057

nvd nist
Published: Oct 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.6
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Exploitability: 3.1 / Impact: 5.8
Source: NVD

Description

On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address binding in the access profile. In the problem scenario, with a hardware-address and IP address configured under address-assignment pool, if a subscriber logging in with DHCP Option 50, the subscriber will not be assigned an available address from the matched pool, but will still get the requested IP address. A malicious DHCP subscriber may be able to utilize this vulnerability to create duplicate IP address assignments, leading to a denial of service for valid subscribers or unauthorized information disclosure via IP address assignment spoofing. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S2, 15.1R8; 16.1 versions prior to 16.1R4-S12, 16.1R7-S2, 16.1R8; 16.2 versions prior to 16.2R2-S7, 16.2R3; 17.1 versions prior to 17.1R2-S9, 17.1R3; 17.2 versions prior to 17.2R1-S7, 17.2R2-S6, 17.2R3; 17.3 versions prior to 17.3R2-S4, 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R2-S3, 18.1R3.

Affected (27)

Products: Juniper: Junos
1 product
Junos
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1
Version 15.1 f2
Version 15.1 f3
Version 15.1 f4
Version 15.1 f5
Version 15.1 f6
Version 15.1 r1
Version 15.1 r2
Version 15.1 r3
Version 15.1 r4
Version 15.1 r5
Version 15.1 r6
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 16.1
Version 16.1 r1
Version 16.1 r2
Version 16.1 r3
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 16.2
Version 16.2 r1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.1
Version 17.1 r1
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 17.2
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.3
Version 17.3 r1
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.4
Version 17.4 r1
Configuration H
2 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 18.1
Version 18.1 r1

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.