PT-2018-1755 · Juniper Networks · Junos

Published

2018-10-10

·

Updated

2019-10-09

·

CVE-2018-0054

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos versions prior to 14.1X53-D47 Junos versions prior to 15.1R7 Junos versions prior to 15.1R8 Junos versions prior to 15.1X53-D233 Junos versions prior to 16.1R7 Junos versions prior to 16.2R3 Junos versions prior to 17.1R2-S9 Junos versions prior to 17.1R3 Junos versions prior to 17.2R2-S6 Junos versions prior to 17.2R3 Junos versions prior to 17.2X75-D42 Junos versions prior to 17.3R3 Junos versions prior to 17.4R2 Junos versions prior to 18.1R2
Description The issue is related to errors in input data processing in Junos, which can cause a denial of service. On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface can cause egress interface congestion, resulting in routing protocol packet drops.
Recommendations For versions prior to 14.1X53-D47, update to 14.1X53-D47 or later. For versions prior to 15.1R7, update to 15.1R7 or later. For versions prior to 15.1R8, update to 15.1R8 or later. For versions prior to 15.1X53-D233, update to 15.1X53-D233 or later. For versions prior to 16.1R7, update to 16.1R7 or later. For versions prior to 16.2R3, update to 16.2R3 or later. For versions prior to 17.1R2-S9, update to 17.1R2-S9 or later. For versions prior to 17.1R3, update to 17.1R3 or later. For versions prior to 17.2R2-S6, update to 17.2R2-S6 or later. For versions prior to 17.2R3, update to 17.2R3 or later. For versions prior to 17.2X75-D42, update to 17.2X75-D42 or later. For versions prior to 17.3R3, update to 17.3R3 or later. For versions prior to 17.4R2, update to 17.4R2 or later. For versions prior to 18.1R2, update to 18.1R2 or later.

Fix

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01355
CVE-2018-0054

Affected Products

Junos