CVE Database
/

CVE-2018-0006

Back to search

CVE-2018-0006

Published: Jan 10, 2018

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

6.5

MEDIUM

Description

A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to excessive memory allocation. This issue only affects devices configured for DHCPv4/v6 over AE auto-sensed VLANs, utilized in Broadband Edge (BBE) deployments. Other configurations are unaffected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R6-S2, 15.1R7; 16.1 versions prior to 16.1R5-S1, 16.1R6; 16.2 versions prior to 16.2R2-S2, 16.2R3; 17.1 versions prior to 17.1R2-S5, 17.1R3; 17.2 versions prior to 17.2R2.

VendorProductVersions

Juniper Networks

Junos OS

affected
15.1 - < 15.1R6-S2, 15.1R7
affected
16.1 - < 16.1R5-S1, 16.1R6
affected
16.2 - < 16.2R2-S2, 16.2R3
affected
17.1 - < 17.1R2-S5, 17.1R3
affected
17.2 - < 17.2R2

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

1040184
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2018-0006 | MEDIUM (6.5) - Security Vulnerability | QwikSec