PT-2018-8590 · Juniper Networks · Junos

Published

2018-10-10

·

Updated

2019-10-09

·

CVE-2018-0058

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Junos OS versions 15.1 through 15.1R7-S1 Junos OS versions 15.1R8 on MX Series Junos OS versions 16.1 through 16.1R4-S10 Junos OS versions 16.1R7 through 16.1R7-S1 Junos OS versions 16.1R8 on MX Series Junos OS versions 16.2 through 16.2R2 Junos OS versions 17.1 through 17.1R2-S8 Junos OS versions 17.1R3 on MX Series Junos OS versions 17.2 through 17.2R2-S5 Junos OS versions 17.2R3 on MX Series Junos OS versions 17.3 through 17.3R2-S3 Junos OS versions 17.3R3 through 17.3R3-S1 Junos OS versions 17.3R4 on MX Series Junos OS versions 17.4 through 17.4R1 Junos OS versions 18.1 through 18.1R2-S2 Junos OS versions 18.1R3 on MX Series Junos OS versions 18.2 through 18.2R1
Description: Receipt of a specially crafted IPv6 exception packet may trigger a kernel crash, causing the device to reboot. This issue is specific to the processing of Broadband Edge client route processing on MX Series subscriber management platforms, introduced by the Tomcat functionality in Junos OS 15.1.
Recommendations: For Junos OS versions 15.1 through 15.1R7-S1, update to 15.1R7-S2 or later. For Junos OS versions 15.1R8 on MX Series, update to a fixed release. For Junos OS versions 16.1 through 16.1R4-S10, update to 16.1R4-S11 or later. For Junos OS versions 16.1R7 through 16.1R7-S1, update to 16.1R7-S2 or later. For Junos OS versions 16.1R8 on MX Series, update to a fixed release. For Junos OS versions 16.2 through 16.2R2, update to 16.2R3 or later. For Junos OS versions 17.1 through 17.1R2-S8, update to 17.1R2-S9 or later. For Junos OS versions 17.1R3 on MX Series, update to a fixed release. For Junos OS versions 17.2 through 17.2R2-S5, update to 17.2R2-S6 or later. For Junos OS versions 17.2R3 on MX Series, update to a fixed release. For Junos OS versions 17.3 through 17.3R2-S3, update to 17.3R2-S4 or later. For Junos OS versions 17.3R3 through 17.3R3-S1, update to 17.3R3-S2 or later. For Junos OS versions 17.3R4 on MX Series, update to a fixed release. For Junos OS versions 17.4 through 17.4R1, update to 17.4R2 or later. For Junos OS versions 18.1 through 18.1R2-S2, update to 18.1R2-S3 or later. For Junos OS versions 18.1R3 on MX Series, update to a fixed release. For Junos OS versions 18.2 through 18.2R1, update to 18.2R1-S1 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0058

Affected Products

Junos