7.5

CVE-2019-0014

On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all interfaces to go down. By continuously sending the offending packet, an attacker can repeatedly crash the FPC process causing a sustained Denial of Service (DoS). This issue affects both IPv4 and IPv6 packet processing. Affected releases are Juniper Networks Junos OS on QFX and PTX Series: 17.4 versions prior to 17.4R2-S1, 17.4R3; 18.1 versions prior to 18.1R3-S1; 18.2 versions prior to 18.2R1-S3, 18.2R2; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D100.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version17.2x75 Updated102
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version17.2x75 Updated50
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version17.2x75 Updated70
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version17.4
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version17.4 Updater1
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version17.4 Updater2
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
JuniperJunos Version18.2 Updater1
   JuniperPtx1000 Version-
   JuniperPtx10002 Version-
   JuniperPtx10008 Version-
   JuniperPtx10016 Version-
   JuniperPtx3000 Version-
   JuniperPtx5000 Version-
   JuniperQfx10002 Version-
   JuniperQfx10008 Version-
   JuniperQfx10016 Version-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5200 Version-
   JuniperQfx5210 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.62
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
sirt@juniper.net 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H