CVE-2017-2300

HIGH

Junos OS SRX Series <12.1X46-D65/<12.3X48-D40/<12.3X48-D60 DoS via Crafted Multicast Packets

Title source: llm
STIX 2.1

Description

On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets.

References (3)

Core 3
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10768
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95400
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037597

Scores

CVSS v3 7.5
EPSS 0.0054
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (5)
juniper/junos < 12.1x46
juniper/junos < 12.3x48 (2 CPE variants)
Juniper Networks/Junos OS on SRX Series Services Gateways chassis cluster 12.1X46 prior to 12.1X46-D65
Juniper Networks/Junos OS on SRX Series Services Gateways chassis cluster 12.3X48 prior to 12.3X48-D40
Juniper Networks/Junos OS on SRX Series Services Gateways chassis cluster 12.3X48 prior to 12.3X48-D60
Published May 30, 2017
Tracked Since Feb 18, 2026