// For flags

CVE-2018-0016

Junos OS: Kernel crash upon receipt of crafted CLNP datagrams

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'clns-routing' or ES-IS is explicitly configured. Devices with without CLNS enabled are not vulnerable to this issue. Devices with IS-IS configured on the interface are not vulnerable to this issue unless CLNS routing is also enabled. This issue only affects devices running Junos OS 15.1. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5; 15.1X49 versions prior to 15.1X49-D60; 15.1X53 versions prior to 15.1X53-D66, 15.1X53-D233, 15.1X53-D471. Earlier releases are unaffected by this vulnerability, and the issue has been resolved in Junos OS 16.1R1 and all subsequent releases.

La recepción de un datagrama CLNP (Connectionless Network Protocol) destinado a la interfaz de un dispositivo Junos OS puede resultar en un cierre inesperado del kernel o conducir a la ejecución remota de código. Los dispositivos solo son vulnerables al datagrama CLNP especialmente manipulado si 'clns-routing' o ES-IS están explícitamente configurados. Los dispositivos sin CLNS habilitado no son vulnerables a este problema. Los dispositivos con IS-IS configurado en la interfaz no son vulnerables, a no ser que el enrutamiento CLNS esté también habilitado. Este problema solo afecta a dispositivos que ejecutan Junos OS 15.1. Las versiones afectadas son Juniper Networks Junos OS: 15.1 en versiones anteriores a la 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5; 15.1X49 en versiones anteriores a la15.1X49-D60; 15.1X53 en versiones anteriores a la 15.1X53-D66, 15.1X53-D233 y 15.1X53-D471. Los lanzamientos anteriores no se han visto afectados por esta vulnerabilidad; el problema se ha resuelto en Junos OS 16.1R1 y en todas las versiones posteriores.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-16 CVE Reserved
  • 2018-04-11 CVE Published
  • 2024-02-19 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r1
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r2
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r3
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r4
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f
Search vendor "Juniper" for product "Junos" and version "15.1f"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f2
Search vendor "Juniper" for product "Junos" and version "15.1f2"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f3
Search vendor "Juniper" for product "Junos" and version "15.1f3"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f4
Search vendor "Juniper" for product "Junos" and version "15.1f4"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f5
Search vendor "Juniper" for product "Junos" and version "15.1f5"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f5
Search vendor "Juniper" for product "Junos" and version "15.1f5"
s1
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f6
Search vendor "Juniper" for product "Junos" and version "15.1f6"
s1
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1f6
Search vendor "Juniper" for product "Junos" and version "15.1f6"
s2
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d10
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d20
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d30
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d35
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d40
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d45
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d50
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d55
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
-
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d10
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d20
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d21
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d30
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d32
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d33
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d34
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d50
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d51
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d52
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d55
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d57
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d58
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d60
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d61
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d62
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d63
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d64
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d65
Affected
in Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
--
Safe