PT-2018-1751 · Juniper Networks · Junos

Published

2018-10-10

·

Updated

2019-10-09

·

CVE-2018-0050

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Junos OS versions prior to 14.1R8-S5 Junos OS versions prior to 14.1R9 Junos OS 14.1X53 versions prior to 14.1X53-D48 on QFX Switching Junos OS 14.1X53 versions prior to 14.1X53-D130 on QFabric System Junos OS 14.2 versions prior to 14.2R4
Description The issue is related to an error handling vulnerability in the Routing Protocols Daemon (RPD) of Juniper Networks Junos OS. This vulnerability allows an attacker to cause RPD to crash by sending a malformed MPLS RSVP packet, potentially leading to a sustained Denial of Service condition. The vulnerability requires the packet to be received on an interface configured to receive this type of traffic. It affects IPv4 but not IPv6.
Recommendations For Junos OS versions prior to 14.1R8-S5, update to version 14.1R8-S5 or later. For Junos OS versions prior to 14.1R9, update to version 14.1R9 or later. For Junos OS 14.1X53 versions prior to 14.1X53-D48 on QFX Switching, update to version 14.1X53-D48 or later. For Junos OS 14.1X53 versions prior to 14.1X53-D130 on QFabric System, update to version 14.1X53-D130 or later. For Junos OS 14.2 versions prior to 14.2R4, update to version 14.2R4 or later.

Fix

DoS

RCE

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01351
CVE-2018-0050

Affected Products

Junos