← Back

CVE-2019-0011

nvd nist
Published: Jan 15, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By continuously sending this type of packet, an attacker can repeatedly crash the kernel causing a sustained Denial of Service. Affected releases are Juniper Networks Junos OS: 17.2 versions prior to 17.2R1-S7, 17.2R3; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S4, 17.4R2; 17.2X75 versions prior to 17.2X75-D110; 18.1 versions prior to 18.1R2.

Affected (27)

Products: Juniper: Junos
1 product
Junos
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.2
Version 17.2 r1-s1
Version 17.2 r1-s2
Version 17.2 r1-s3
Version 17.2 r1-s4
Version 17.2 r1-s5
Version 17.2 r1-s6
Version 17.2 r1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.3
Version 17.3 r1
Version 17.3 r2
Version 17.3 r3-s1
Version 17.3 r3-s2
Version 17.3 r3
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.4
Version 17.4 r1-s1
Version 17.4 r1-s2
Version 17.4 r1-s3
Version 17.4 r1
Configuration D
7 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 17.2x75
Version 17.2x75 d100
Version 17.2x75 d102
Version 17.2x75 d50
Version 17.2x75 d70
Version 17.2x75 d90
Version 17.2x75 d92
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 18.1

References (4)

Source: sirt@juniper.net
Broken LinkThird Party AdvisoryVDB Entry
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.