PT-2019-1976 · Juniper Networks · Junos

Published

2019-04-10

·

Updated

2020-09-29

·

CVE-2019-0031

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions prior to 17.4R2 Junos OS versions prior to 18.1R2
Description The issue is related to the jdhcpd daemon in Junos OS, which can cause a memory resource consumption problem when receiving specific IPv6 DHCP packets. This can lead to a Denial of Service (DoS) condition, impacting both IPv4 and IPv6 requests. Additionally, some clients may not have their IPv6 Identity Association (IA) address and network tables agreed upon by the jdhcpd daemon after a failover event, resulting in denied interfaces and IP addresses.
Recommendations For Junos OS versions prior to 17.4R2, update to version 17.4R2 or later to resolve the issue. For Junos OS versions prior to 18.1R2, update to version 18.1R2 or later to resolve the issue.

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01666
CVE-2019-0031

Affected Products

Junos