CVE-2018-0005

HIGH

Juniper Junos OS - Denial of Service via MAC Move Limit Handling

Title source: llm
STIX 2.1

Description

QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or other unintended conditions. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D40; 15.1X53 versions prior to 15.1X53-D55; 15.1 versions prior to 15.1R7.

References (2)

Core 2
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10833
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040182

Scores

CVSS v3 7.4
EPSS 0.0022
EPSS Percentile 45.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-754
Status published
Products (3)
juniper/junos 14.1x53 (9 CPE variants)
juniper/junos 15.1 r1 (6 CPE variants)
juniper/junos 15.1x53 d20 (9 CPE variants)
Published Jan 10, 2018
Tracked Since Feb 18, 2026