9.8

CVE-2019-0002

On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take effect. When this issue occurs, the output of the command: show pfe filter hw summary will not show the entry for: RACL group Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions prior to 15.1X53-D590; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2. This issue affect both IPv4 and IPv6 firewall filter.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version15.1x53 Updated50
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated51
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated52
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated55
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated57
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated58
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated59
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Update-
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Updater1
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Updater2
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Updater2-s1
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Updater2-s2
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.1 Updater2-s4
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.2 Update-
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.2 Updater1
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.2 Updater1-s3
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.2 Updater1-s4
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version18.2 Updater1-s5
   JuniperEx2300 Version-
   JuniperEx3400 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.521
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
sirt@juniper.net 5.8 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWE-794 Incomplete Filtering of Multiple Instances of Special Elements

The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstream component.