PT-2017-11405 · Juniper Networks · Srx+1
Published
2017-10-13
·
Updated
2019-10-09
·
CVE-2017-10608
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions 12.1X46 prior to 12.1X46-D55 on SRX
Juniper Networks Junos OS versions 12.1X47 prior to 12.1X47-D45 on SRX
Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D32 on SRX
Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D35 on SRX
Juniper Networks Junos OS versions 15.1X49 prior to 15.1X49-D60 on SRX
Description
A denial of service issue exists in the Sun/MS-RPC ALG services component of Junos OS, allowing an attacker to cause a repeated denial of service against the target. This issue affects IPv6 traffic and can cause the flowd daemon to halt traffic on all nodes in a cluster. The issue is not related to HA services and only affects Juniper Networks SRX series devices with one or more ALGs enabled.
Recommendations
For Juniper Networks Junos OS versions 12.1X46 prior to 12.1X46-D55 on SRX, update to version 12.1X46-D55 or later.
For Juniper Networks Junos OS versions 12.1X47 prior to 12.1X47-D45 on SRX, update to version 12.1X47-D45 or later.
For Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D32 on SRX, update to version 12.3X48-D32 or later.
For Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D35 on SRX, update to version 12.3X48-D35 or later.
For Juniper Networks Junos OS versions 15.1X49 prior to 15.1X49-D60 on SRX, update to version 15.1X49-D60 or later.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos
Srx