data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0038 – SRX Series: Crafted packets destined to fxp0 management interface on SRX340/SRX345 devices can lead to DoS
https://notcve.org/view.php?id=CVE-2019-0038
10 Apr 2019 — Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are affected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D160 on SRX340/SRX345; 17.3 on SRX340/SRX345; 17.4 versions prior to 17.4R2-S3, 17.4R3 on SRX340/SRX345; 18.1 versions... • http://www.securityfocus.com/bid/107873 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0037 – Junos OS: jdhcpd crash upon receipt of crafted DHCPv6 solicit message
https://notcve.org/view.php?id=CVE-2019-0037
10 Apr 2019 — In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solicit messages received from a DHCPv6 client. By continuously sending the same crafted packet, an attacker can repeatedly crash the jdhcpd process causing a sustained Denial of Service (DoS) to both IPv4 and IPv6 clients. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D171, 15.1X49-D... • http://www.securityfocus.com/bid/107894 •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0036 – Junos OS: Firewall filter terms named "internal-1" and "internal-2" being ignored
https://notcve.org/view.php?id=CVE-2019-0036
10 Apr 2019 — When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed without error, but the filter criteria will match all packets leading to unexpected results. Affected releases are Juniper Networks Junos OS: All versions prior to and including 12.3; 14.1X53 versions prior to 14.1X53-D130, 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-... • https://kb.juniper.net/JSA10925 • CWE-284: Improper Access Control CWE-754: Improper Check for Unusual or Exceptional Conditions •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0035 – Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
https://notcve.org/view.php?id=CVE-2019-0035
10 Apr 2019 — When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Operations, Administration, and Maintenance) volume, leading to a possible administrative bypass with physical access to the console. OAM volumes (e.g. flash drives) are typically instantiated as /dev/gpt/oam, or /oam for short. Password recovery, changing the root password f... • https://kb.juniper.net/JSA10924 • CWE-501: Trust Boundary Violation CWE-522: Insufficiently Protected Credentials •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0019 – BGP packets can trigger rpd crash when BGP tracing is enabled.
https://notcve.org/view.php?id=CVE-2019-0019
10 Apr 2019 — When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S... • http://www.securityfocus.com/bid/107893 • CWE-404: Improper Resource Shutdown or Release •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0008 – QFX5000 Series, EX4300, EX4600: A stack buffer overflow vulnerability in Packet Forwarding Engine manager (FXPC) process
https://notcve.org/view.php?id=CVE-2019-0008
10 Apr 2019 — A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. Affected releases are Juniper Networks Junos OS on QFX 5000 series, EX4300, EX4600 are: 14.1X53; 15.1X53 versions prior to 15.1X53-D235; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versi... • http://www.securityfocus.com/bid/107897 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0002 – Junos OS: EX2300 and EX3400 series: Certain stateless firewall filter rules might not take effect
https://notcve.org/view.php?id=CVE-2019-0002
15 Jan 2019 — On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take effect. When this issue occurs, the output of the command: show pfe filter hw summary will not show the entry for: RACL group Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions prior to 15.1X53-D590; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2. This issue affect both IPv4 and IPv6 firewall filter. En las series EX2300 ... • http://www.securityfocus.com/bid/106669 • CWE-794: Incomplete Filtering of Multiple Instances of Special Elements •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0001 – Junos OS: MX Series: uncontrolled recursion and crash in Broadband Edge subscriber management daemon (bbe-smgd).
https://notcve.org/view.php?id=CVE-2019-0001
15 Jan 2019 — Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeated receipt of the same packet can result in an extended denial of service condition for the device. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S1; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 1... • http://www.securityfocus.com/bid/106541 • CWE-674: Uncontrolled Recursion •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0014 – Junos OS: QFX and PTX Series: FPC process crashes after J-Flow processes a malformed packet
https://notcve.org/view.php?id=CVE-2019-0014
15 Jan 2019 — On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all interfaces to go down. By continuously sending the offending packet, an attacker can repeatedly crash the FPC process causing a sustained Denial of Service (DoS). This issue affects both IPv4 and IPv6 packet processing. Affected releases are Juniper Networks Junos OS on QFX and PTX Series: 17.4 versions prior to 17.4R2-S1, 17.4R3; 18.1 versions prior to 18.1R3-S1;... • http://www.securityfocus.com/bid/106556 • CWE-19: Data Processing Errors •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2019-0009 – Junos OS: EX2300 and EX3400: High disk I/O operations may disrupt the communication between RE and PFE
https://notcve.org/view.php?id=CVE-2019-0009
15 Jan 2019 — On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine (PFE). In a virtual chassis (VC) deployment, this issue disrupts communication between the VC members. This issue does not affect other Junos platforms. Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions prior to 15.1X53-D590; 18.1 versions prior to 18.1R2-S2, 18.1R3; 18.2 versions prior to 18.2R2. En las series EX2300 y EX3400, las op... • http://www.securityfocus.com/bid/106548 •