PT-2018-8581 · Juniper Networks · Junos

Publicado

2018-07-11

·

Atualizado

2019-10-09

·

CVE-2018-0037

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions 15.1F5-S7 through 15.1F6-S9 Junos OS versions 15.1F6-S10 is not affected, but versions prior to 15.1F6-S10 are affected, so the correct range is: Junos OS versions 15.1F5-S7 through 15.1F6-S9 Junos OS versions 15.1R5 through 15.1R6-S5 Junos OS versions 15.1R7 and earlier
Description: The Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. An attacker can cause a sustained Denial of Service by continuously sending crafted BGP NOTIFICATION messages, crashing the RPD process. This issue only affects the receiving BGP device and is non-transitive in nature.
Recommendations: For Junos OS versions 15.1F5-S7 through 15.1F6-S9, update to version 15.1F6-S10 or later. For Junos OS versions 15.1R5 through 15.1R6-S5, update to version 15.1R6-S6 or later. For Junos OS versions 15.1R7 and earlier, update to version 15.1R7 or later, but since 16.1R1 is mentioned as not affected, it is recommended to update to 16.1R1 or later to ensure the issue is resolved.

Correção

RCE

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0037

Produtos afetados

Junos