PT-2018-8588 · Juniper Networks · Junos

Published

2018-10-10

·

Updated

2019-10-09

·

CVE-2018-0056

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions prior to 15.1R7-S1 on MX Series Junos OS versions prior to 16.1R4-S12 on MX Series Junos OS versions prior to 16.1R6-S6 on MX Series Junos OS versions prior to 16.2R2-S7 on MX Series Junos OS versions prior to 17.1R2-S9 on MX Series Junos OS versions prior to 17.2R1-S7 on MX Series Junos OS versions prior to 17.2R2-S6 on MX Series Junos OS versions prior to 17.3R2-S4 on MX Series Junos OS versions prior to 17.3R3-S1 on MX Series Junos OS versions prior to 17.4R1-S5 on MX Series Junos OS versions prior to 18.1R2 on MX Series
Description: The Layer 2 Address Learning Daemon (L2ALD) daemon may crash when attempting to delete a duplicate MAC address that is not found in the internal MAC address table. This issue occurs when a duplicate MAC address is learned by two different interfaces on an MX Series device with l2-backhaul VPN configured.
Recommendations: For Junos OS versions prior to 15.1R7-S1 on MX Series, update to 15.1R7-S1 or later. For Junos OS versions prior to 16.1R4-S12 on MX Series, update to 16.1R4-S12 or later. For Junos OS versions prior to 16.1R6-S6 on MX Series, update to 16.1R6-S6 or later. For Junos OS versions prior to 16.2R2-S7 on MX Series, update to 16.2R2-S7 or later. For Junos OS versions prior to 17.1R2-S9 on MX Series, update to 17.1R2-S9 or later. For Junos OS versions prior to 17.2R1-S7 on MX Series, update to 17.2R1-S7 or later. For Junos OS versions prior to 17.2R2-S6 on MX Series, update to 17.2R2-S6 or later. For Junos OS versions prior to 17.3R2-S4 on MX Series, update to 17.3R2-S4 or later. For Junos OS versions prior to 17.3R3-S1 on MX Series, update to 17.3R3-S1 or later. For Junos OS versions prior to 17.4R1-S5 on MX Series, update to 17.4R1-S5 or later. For Junos OS versions prior to 18.1R2 on MX Series, update to 18.1R2 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0056

Affected Products

Junos