CVE-2019-0003

MEDIUM

Junos OS DoS via BGP FlowSpec Configuration

Title source: llm
STIX 2.1

Description

When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash with a core file being generated. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 15.1 versions prior to 15.1R3; 15.1F versions prior to 15.1F3; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10902
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106544

Scores

CVSS v3 5.9
EPSS 0.0062
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-617
Status published
Products (4)
juniper/junos 12.1x46 (12 CPE variants)
juniper/junos 12.3 (12 CPE variants)
juniper/junos 12.3x48 d10 (11 CPE variants)
juniper/junos 14.1x53 (15 CPE variants)
Published Jan 15, 2019
Tracked Since Feb 18, 2026