← Back

CVE-2019-0008

nvd nist
Published: Apr 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. Affected releases are Juniper Networks Junos OS on QFX 5000 series, EX4300, EX4600 are: 14.1X53; 15.1X53 versions prior to 15.1X53-D235; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3-S2, 17.3R4; 17.4 versions prior to 17.4R2-S1, 17.4R3; 18.1 versions prior to 18.1R3-S1, 18.1R4; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R2.

Affected (13)

Products: Juniper: Junos
1 product
Junos
Configuration A
13 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Juniper
From 15.1x53 to 15.1x53-d235
From 17.1 to 17.1r3
From 17.2 to 17.2r3
From 17.3 to 17.3r3-s2
From 17.4 to 17.4r2-s1
From 18.1 to 18.1r3-s1
From 18.2 to 18.2r2
From 18.2x75 to 18.2x75-d30
From 18.3 to 18.3r2
Version 14.1x53
Version 17.3
Version 17.4
Version 18.1
Running on/withPlatform Versions
Juniper
Ex4300
All versions
Juniper
Ex4300m
All versions
Juniper
Ex4600
All versions
Juniper
Ex4650
All versions
Juniper
Qfx5100
All versions
Juniper
Qfx5110
All versions
Juniper
Qfx5120
All versions
Juniper
Qfx5200 32c
All versions
Juniper
Qfx5200 48y
All versions
Juniper
Qfx5210 64c
All versions

References (4)

Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.