CVE Database
/

CVE-2019-0014

Back to search

CVE-2019-0014

Published: Jan 15, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all interfaces to go down. By continuously sending the offending packet, an attacker can repeatedly crash the FPC process causing a sustained Denial of Service (DoS). This issue affects both IPv4 and IPv6 packet processing. Affected releases are Juniper Networks Junos OS on QFX and PTX Series: 17.4 versions prior to 17.4R2-S1, 17.4R3; 18.1 versions prior to 18.1R3-S1; 18.2 versions prior to 18.2R1-S3, 18.2R2; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D100.

VendorProductVersions

Juniper Networks

Junos OS

affected
17.4 - < 17.4R2-S1, 17.4R3
affected
18.1 - < 18.1R3-S1, 18.1R4
affected
18.2 - < 18.2R1-S3, 18.2R2
affected
17.2X75 - < 17.2X75-D91, 17.2X75-D100

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

106556
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now