← Back

CVE-2019-0038

nvd nist
Published: Apr 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are affected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D160 on SRX340/SRX345; 17.3 on SRX340/SRX345; 17.4 versions prior to 17.4R2-S3, 17.4R3 on SRX340/SRX345; 18.1 versions prior to 18.1R3-S1 on SRX340/SRX345; 18.2 versions prior to 18.2R2 on SRX340/SRX345; 18.3 versions prior to 18.3R1-S2, 18.3R2 on SRX340/SRX345. This issue does not affect Junos OS releases prior to 15.1X49 on any platform.

Affected (31)

Products: Juniper: Junos
1 product
Junos
Configuration A
31 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1x49
Version 15.1x49 d10
Version 15.1x49 d150
Version 15.1x49 d20
Version 15.1x49 d30
Version 15.1x49 d35
Version 15.1x49 d40
Version 15.1x49 d45
Version 15.1x49 d50
Version 15.1x49 d55
Version 15.1x49 d60
Version 15.1x49 d65
Version 15.1x49 d70
Version 15.1x49 d75
Version 15.1x49 d80
Version 17.3
Version 17.4
Version 17.4 r2-s1
Version 17.4 r2-s2
Version 18.1
Version 18.1 r1
Version 18.1 r2-s1
Version 18.1 r2-s2
Version 18.1 r2
Version 18.1 r3
Version 18.2
Version 18.2 r1
Version 18.3
Version 18.3 r1-s1
Version 18.3 r1
Version 18.3 r2
Running on/withPlatform Versions
Juniper
Srx340
All versions
Juniper
Srx345
All versions

References (4)

Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.