6.8

CVE-2018-0017

SRX Series: Denial of service vulnerability in flowd daemon on devices configured with NAT-PT

A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series devices may allow a certain valid IPv6 packet to crash the flowd daemon. Repeated crashes of the flowd daemon can result in an extended denial of service condition for the SRX device. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D72; 12.3X48 versions prior to 12.3X48-D55; 15.1X49 versions prior to 15.1X49-D90.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version >= 12.1x46 <= 12.1x46\:d72
Juniper ≫ Junos Version >= 12.3x48 <= 12.3x48\:d55
Juniper ≫ Junos Version >= 15.1x49 <= 15.1x49\:d90
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
Juniper 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/103749
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040785
Third Party Advisory
VDB Entry
https://kb.juniper.net/JSA10845
Vendor Advisory