7.5

CVE-2017-2314

Junos: RPD crash due to malformed BGP OPEN message

Receipt of a malformed BGP OPEN message may cause the routing protocol daemon (rpd) process to crash and restart. By continuously sending specially crafted BGP OPEN messages, an attacker can repeatedly crash the rpd process causing prolonged denial of service. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.3 prior to 12.3R12-S4, 12.3R13, 12.3R3-S4; 12.3X48 prior to 12.3X48-D50; 13.3 prior to 13.3R4-S11, 13.3R10; 14.1 prior to 14.1R8-S3, 14.1R9; 14.1X53 prior to 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R4-S7, 14.2R6-S4, 14.2R7; 15.1 prior to 15.1F2-S11, 15.1F4-S1-J1, 15.1F5-S3, 15.1F6, 15.1R4; 15.1X49 prior to 15.1X49-D100; 15.1X53 prior to 15.1X53-D33, 15.1X53-D50.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 12.3
Juniper ≫ Junos Version 12.3 Update r1
Juniper ≫ Junos Version 12.3 Update r10
Juniper ≫ Junos Version 12.3 Update r11
Juniper ≫ Junos Version 12.3 Update r12
Juniper ≫ Junos Version 12.3 Update r2
Juniper ≫ Junos Version 12.3 Update r3
Juniper ≫ Junos Version 12.3 Update r4
Juniper ≫ Junos Version 12.3 Update r5
Juniper ≫ Junos Version 12.3 Update r6
Juniper ≫ Junos Version 12.3 Update r7
Juniper ≫ Junos Version 12.3 Update r8
Juniper ≫ Junos Version 12.3 Update r9
Juniper ≫ Junos Version 12.3x48 Update -
Juniper ≫ Junos Version 12.3x48 Update d10
Juniper ≫ Junos Version 12.3x48 Update d15
Juniper ≫ Junos Version 12.3x48 Update d20
Juniper ≫ Junos Version 12.3x48 Update d25
Juniper ≫ Junos Version 12.3x48 Update d30
Juniper ≫ Junos Version 12.3x48 Update d35
Juniper ≫ Junos Version 12.3x48 Update d40
Juniper ≫ Junos Version 12.3x48 Update d45
Juniper ≫ Junos Version 14.1
Juniper ≫ Junos Version 14.1 Update r1
Juniper ≫ Junos Version 14.1 Update r2
Juniper ≫ Junos Version 14.1 Update r3
Juniper ≫ Junos Version 14.1 Update r4
Juniper ≫ Junos Version 14.1 Update r5
Juniper ≫ Junos Version 14.1 Update r6
Juniper ≫ Junos Version 14.1 Update r7
Juniper ≫ Junos Version 14.1 Update r8
Juniper ≫ Junos Version 14.1x53 Update -
Juniper ≫ Junos Version 14.1x53 Update d15
Juniper ≫ Junos Version 14.1x53 Update d16
Juniper ≫ Junos Version 14.1x53 Update d25
Juniper ≫ Junos Version 14.1x53 Update d26
Juniper ≫ Junos Version 14.1x53 Update d27
Juniper ≫ Junos Version 14.1x53 Update d30
Juniper ≫ Junos Version 14.1x53 Update d35
Juniper ≫ Junos Version 14.2
Juniper ≫ Junos Version 14.2 Update r1
Juniper ≫ Junos Version 14.2 Update r2
Juniper ≫ Junos Version 14.2 Update r3
Juniper ≫ Junos Version 14.2 Update r4
Juniper ≫ Junos Version 14.2 Update r5
Juniper ≫ Junos Version 14.2 Update r6
Juniper ≫ Junos Version 15.1
Juniper ≫ Junos Version 15.1 Update f2
Juniper ≫ Junos Version 15.1 Update f4
Juniper ≫ Junos Version 15.1 Update f5
Juniper ≫ Junos Version 13.3
Juniper ≫ Junos Version 13.3 Update r1
Juniper ≫ Junos Version 13.3 Update r2
Juniper ≫ Junos Version 13.3 Update r3
Juniper ≫ Junos Version 13.3 Update r9
Juniper ≫ Junos Version 14.1x55
Juniper ≫ Junos Version 15.1x49 Update d10
Juniper ≫ Junos Version 15.1x49 Update d20
Juniper ≫ Junos Version 15.1x49 Update d30
Juniper ≫ Junos Version 15.1x49 Update d35
Juniper ≫ Junos Version 15.1x49 Update d40
Juniper ≫ Junos Version 15.1x49 Update d45
Juniper ≫ Junos Version 15.1x49 Update d50
Juniper ≫ Junos Version 15.1x49 Update d55
Juniper ≫ Junos Version 15.1x49 Update d60
Juniper ≫ Junos Version 15.1x49 Update d65
Juniper ≫ Junos Version 15.1x49 Update d70
Juniper ≫ Junos Version 15.1x49 Update d75
Juniper ≫ Junos Version 15.1x49 Update d80
Juniper ≫ Junos Version 15.1x49 Update d90
Juniper ≫ Junos Version 15.1x53 Update d10
Juniper ≫ Junos Version 15.1x53 Update d20
Juniper ≫ Junos Version 15.1x53 Update d21
Juniper ≫ Junos Version 15.1x53 Update d30
Juniper ≫ Junos Version 15.1x53 Update d32
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.666
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Juniper 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securitytracker.com/id/1038889
Third Party Advisory
VDB Entry
https://kb.juniper.net/JSA10779
Vendor Advisory