5.3

CVE-2018-0056

MX Series: L2ALD daemon may crash if a duplicate MAC is learned by two different interfaces

If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to delete the duplicate MAC address when the particular entry is not found in the internal MAC address table. This issue only occurs on MX Series devices with l2-backhaul VPN configured. No other products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S1 on MX Series; 16.1 versions prior to 16.1R4-S12, 16.1R6-S6 on MX Series; 16.2 versions prior to 16.2R2-S7 on MX Series; 17.1 versions prior to 17.1R2-S9 on MX Series; 17.2 versions prior to 17.2R1-S7, 17.2R2-S6 on MX Series; 17.3 versions prior to 17.3R2-S4, 17.3R3-S1 on MX Series; 17.4 versions prior to 17.4R1-S5 on MX Series; 18.1 versions prior to 18.1R2 on MX Series.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 15.1
Juniper ≫ Junos Version 15.1 Update f2
Juniper ≫ Junos Version 15.1 Update f3
Juniper ≫ Junos Version 15.1 Update f4
Juniper ≫ Junos Version 15.1 Update f5
Juniper ≫ Junos Version 15.1 Update f6
Juniper ≫ Junos Version 15.1 Update r1
Juniper ≫ Junos Version 15.1 Update r2
Juniper ≫ Junos Version 15.1 Update r3
Juniper ≫ Junos Version 15.1 Update r4
Juniper ≫ Junos Version 15.1 Update r5
Juniper ≫ Junos Version 15.1 Update r6
Juniper ≫ Junos Version 16.1
Juniper ≫ Junos Version 16.1 Update r1
Juniper ≫ Junos Version 16.1 Update r2
Juniper ≫ Junos Version 16.1 Update r3
Juniper ≫ Junos Version 16.2
Juniper ≫ Junos Version 16.2 Update r1
Juniper ≫ Junos Version 17.1
Juniper ≫ Junos Version 17.1 Update r1
Juniper ≫ Junos Version 17.2
Juniper ≫ Junos Version 17.3
Juniper ≫ Junos Version 17.3 Update r1
Juniper ≫ Junos Version 17.4
Juniper ≫ Junos Version 17.4 Update r1
Juniper ≫ Junos Version 18.1
Juniper ≫ Junos Version 18.1 Update r1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.446
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 1.6 3.6
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P
Juniper 6.5 2.8 3.6
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securitytracker.com/id/1041857
Third Party Advisory
VDB Entry
https://kb.juniper.net/JSA10890
Vendor Advisory