CVE-2018-0002

HIGH

Junos OS Multiple Versions - Denial of Service via Crafted TCP/IP Packet

Title source: llm
STIX 2.1

Description

On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed through the device results in memory corruption leading to a flowd daemon crash. Sustained crafted response packets lead to repeated crashes of the flowd daemon which results in an extended Denial of Service condition. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D60 on SRX series; 12.3X48 versions prior to 12.3X48-D35 on SRX series; 14.1 versions prior to 14.1R9 on MX series; 14.2 versions prior to 14.2R8 on MX series; 15.1X49 versions prior to 15.1X49-D60 on SRX series; 15.1 versions prior to 15.1R5-S8, 15.1F6-S9, 15.1R6-S4, 15.1R7 on MX series; 16.1 versions prior to 16.1R6 on MX series; 16.2 versions prior to 16.2R3 on MX series; 17.1 versions prior to 17.1R2-S4, 17.1R3 on MX series. No other Juniper Networks products or platforms are affected by this issue.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040178
Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10829

Scores

CVSS v3 8.2
EPSS 0.0184
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Details

CWE
CWE-119
Status published
Products (7)
juniper/junos 12.1x46 d10 (10 CPE variants)
juniper/junos 12.3x48 d10 (5 CPE variants)
juniper/junos 14.1 r1 (8 CPE variants)
juniper/junos 14.2 r1 (7 CPE variants)
juniper/junos 15.1x49 d10 (10 CPE variants)
juniper/junos 15.1 f6-s9 (7 CPE variants)
juniper/junos 16.1 r1 (3 CPE variants)
Published Jan 10, 2018
Tracked Since Feb 18, 2026