6.5

CVE-2019-0011

Junos OS: Kernel crash after processing specific incoming packet to the out of band management interface (CVE-2019-0011)

The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By continuously sending this type of packet, an attacker can repeatedly crash the kernel causing a sustained Denial of Service. Affected releases are Juniper Networks Junos OS: 17.2 versions prior to 17.2R1-S7, 17.2R3; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S4, 17.4R2; 17.2X75 versions prior to 17.2X75-D110; 18.1 versions prior to 18.1R2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 17.2 Update -
Juniper ≫ Junos Version 17.2 Update r1
Juniper ≫ Junos Version 17.2 Update r1-s1
Juniper ≫ Junos Version 17.2 Update r1-s2
Juniper ≫ Junos Version 17.2 Update r1-s3
Juniper ≫ Junos Version 17.2 Update r1-s4
Juniper ≫ Junos Version 17.2 Update r1-s5
Juniper ≫ Junos Version 17.2 Update r1-s6
Juniper ≫ Junos Version 17.3 Update -
Juniper ≫ Junos Version 17.3 Update r1
Juniper ≫ Junos Version 17.3 Update r2
Juniper ≫ Junos Version 17.3 Update r3
Juniper ≫ Junos Version 17.3 Update r3-s1
Juniper ≫ Junos Version 17.3 Update r3-s2
Juniper ≫ Junos Version 17.4 Update -
Juniper ≫ Junos Version 17.4 Update r1
Juniper ≫ Junos Version 17.4 Update r1-s1
Juniper ≫ Junos Version 17.4 Update r1-s2
Juniper ≫ Junos Version 17.4 Update r1-s3
Juniper ≫ Junos Version 17.2x75 Update -
Juniper ≫ Junos Version 17.2x75 Update d100
Juniper ≫ Junos Version 17.2x75 Update d102
Juniper ≫ Junos Version 17.2x75 Update d50
Juniper ≫ Junos Version 17.2x75 Update d70
Juniper ≫ Junos Version 17.2x75 Update d90
Juniper ≫ Junos Version 17.2x75 Update d92
Juniper ≫ Junos Version 18.1 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.457
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
Juniper 6.5 2.8 3.6
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/106534
Third Party Advisory
Broken Link
VDB Entry
https://kb.juniper.net/JSA10911
Vendor Advisory