CVE Database
/

CVE-2018-0062

Back to search

CVE-2018-0062

Published: Oct 10, 2018

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service which may prevent other users to authenticate or to perform J-Web operations. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D60 on SRX Series; 15.1 versions prior to 15.1R7; 15.1F6; 15.1X49 versions prior to 15.1X49-D120 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D234 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D470, 15.1X53-D495 on NFX Series; 16.1 versions prior to 16.1R6; 16.2 versions prior to 16.2R2-S6, 16.2R3; 17.1 versions prior to 17.1R2-S6, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R2. No other Juniper Networks products or platforms are affected by this issue.

VendorProductVersions

Juniper Networks

Junos OS

affected
12.1X46 - < 12.1X46-D77
affected
12.3X48 - < 12.3X48-D60
affected
15.1X49 - < 15.1X49-D120

Juniper Networks

Junos OS

affected
15.1F6
affected
12.3 - < 12.3R12-S10
affected
15.1 - < 15.1R7
affected
16.1 - < 16.1R6
affected
16.2 - < 16.2R2-S6, 16.2R3

+3 more versions

Juniper Networks

Junos OS

affected
15.1X53 - < 15.1X53-D59

Juniper Networks

Junos OS

affected
15.1X53 - < 15.1X53-D67

Juniper Networks

Junos OS

affected
15.1X53 - < 15.1X53-D234

Juniper Networks

Junos OS

affected
15.1X53 - < 15.1X53-D470, 15.1X53-D495

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

References

1041860
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now