// For flags

CVE-2018-0002

MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with ALG enabled.

Severity Score

5.9
*CVSS v3

Exploit Likelihood

1.8%
*EPSS

Affected Versions

810
*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed through the device results in memory corruption leading to a flowd daemon crash. Sustained crafted response packets lead to repeated crashes of the flowd daemon which results in an extended Denial of Service condition. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D60 on SRX series; 12.3X48 versions prior to 12.3X48-D35 on SRX series; 14.1 versions prior to 14.1R9 on MX series; 14.2 versions prior to 14.2R8 on MX series; 15.1X49 versions prior to 15.1X49-D60 on SRX series; 15.1 versions prior to 15.1R5-S8, 15.1F6-S9, 15.1R6-S4, 15.1R7 on MX series; 16.1 versions prior to 16.1R6 on MX series; 16.2 versions prior to 16.2R3 on MX series; 17.1 versions prior to 17.1R2-S4, 17.1R3 on MX series. No other Juniper Networks products or platforms are affected by this issue.

En dispositivos de las series SRX y MX con un Service PIC con cualquier ALG habilitado, un paquete de respuesta TCP/IP manipulado procesado por el dispositivo resulta en una corrupción de memoria que provoca que el demonio flowd se cierre de manera inesperada. Los paquetes de respuesta manipulados sostenidos provocan cierres inesperados repetidos del demonio flowd, lo que resulta en una condición de Denegación de servicio (DoS) extendida. Las distribuciones afectadas son Juniper Networks Junos OS: 12.1X46 anteriores a 12.1X46-D60 en SRX series; 12.3X48 anteriores a 12.3X48-D35 en SRX series; 14.1 anteriores a 14.1R9 en MX series; 14.2 anteriores a 14.2R8 en MX series; 15.1X49 anteriores a 15.1X49-D60 en SRX series; 15.1 anteriores a 15.1R5-S8, 15.1F6-S9, 15.1R6-S4, 15.1R7 en MX series; 16.1 anteriores a 16.1R6 en MX series; 16.2 anteriores a 16.2R3 en MX series; 17.1 anteriores a 17.1R2-S4, 17.1R3 en MX series. No hay ningún otro producto o plataforma de Juniper Networks que se vea afectado por este problema.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-16 CVE Reserved
  • 2018-01-10 CVE Published
  • 2024-09-16 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions (810)