PT-2017-11405 · Juniper Networks · Srx+1

Published

2017-10-13

·

Updated

2019-10-09

·

CVE-2017-10608

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions 12.1X46 prior to 12.1X46-D55 on SRX Juniper Networks Junos OS versions 12.1X47 prior to 12.1X47-D45 on SRX Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D32 on SRX Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D35 on SRX Juniper Networks Junos OS versions 15.1X49 prior to 15.1X49-D60 on SRX
Description A denial of service issue exists in the Sun/MS-RPC ALG services component of Junos OS, allowing an attacker to cause a repeated denial of service against the target. This issue affects IPv6 traffic and can cause the flowd daemon to halt traffic on all nodes in a cluster. The issue is not related to HA services and only affects Juniper Networks SRX series devices with one or more ALGs enabled.
Recommendations For Juniper Networks Junos OS versions 12.1X46 prior to 12.1X46-D55 on SRX, update to version 12.1X46-D55 or later. For Juniper Networks Junos OS versions 12.1X47 prior to 12.1X47-D45 on SRX, update to version 12.1X47-D45 or later. For Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D32 on SRX, update to version 12.3X48-D32 or later. For Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D35 on SRX, update to version 12.3X48-D35 or later. For Juniper Networks Junos OS versions 15.1X49 prior to 15.1X49-D60 on SRX, update to version 15.1X49-D60 or later.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10608

Affected Products

Junos
Srx