CVE-2019-0038

MEDIUM

Juniper Junos OS 15.1X49-18.3 - Denial of Service via Crafted Packets to Management Interface

Title source: llm
STIX 2.1

Description

Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are affected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D160 on SRX340/SRX345; 17.3 on SRX340/SRX345; 17.4 versions prior to 17.4R2-S3, 17.4R3 on SRX340/SRX345; 18.1 versions prior to 18.1R3-S1 on SRX340/SRX345; 18.2 versions prior to 18.2R2 on SRX340/SRX345; 18.3 versions prior to 18.3R1-S2, 18.3R2 on SRX340/SRX345. This issue does not affect Junos OS releases prior to 15.1X49 on any platform.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10927
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107873

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770 CWE-400
Status published
Products (6)
juniper/junos 15.1x49 (15 CPE variants)
juniper/junos 17.3
juniper/junos 17.4 (3 CPE variants)
juniper/junos 18.1 (6 CPE variants)
juniper/junos 18.2 (2 CPE variants)
juniper/junos 18.3 (4 CPE variants)
Published Apr 10, 2019
Tracked Since Feb 18, 2026