CVE Database
/

CVE-2019-0011

Back to search

CVE-2019-0011

Published: Jan 15, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

6.5

MEDIUM

Description

The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By continuously sending this type of packet, an attacker can repeatedly crash the kernel causing a sustained Denial of Service. Affected releases are Juniper Networks Junos OS: 17.2 versions prior to 17.2R1-S7, 17.2R3; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S4, 17.4R2; 17.2X75 versions prior to 17.2X75-D110; 18.1 versions prior to 18.1R2.

VendorProductVersions

Juniper Networks

Junos OS

affected
17.2 - < 17.2R1-S7, 17.2R3
affected
17.3 - < 17.3R3-S3
affected
17.4 - < 17.4R1-S4, 17.4R2
affected
17.2X75 - < 17.2X75-D110
affected
18.1 - < 18.1R2

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

106534
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now