CVE-2019-0038
MEDIUMJuniper Junos OS 15.1X49-18.3 - Denial of Service via Crafted Packets to Management Interface
Title source: llmDescription
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are affected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D160 on SRX340/SRX345; 17.3 on SRX340/SRX345; 17.4 versions prior to 17.4R2-S3, 17.4R3 on SRX340/SRX345; 18.1 versions prior to 18.1R3-S1 on SRX340/SRX345; 18.2 versions prior to 18.2R2 on SRX340/SRX345; 18.3 versions prior to 18.3R1-S2, 18.3R2 on SRX340/SRX345. This issue does not affect Junos OS releases prior to 15.1X49 on any platform.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA10927
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107873
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
44.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-770
CWE-400
Status
published
Products (6)
juniper/junos
15.1x49 (15 CPE variants)
juniper/junos
17.3
juniper/junos
17.4 (3 CPE variants)
juniper/junos
18.1 (6 CPE variants)
juniper/junos
18.2 (2 CPE variants)
juniper/junos
18.3 (4 CPE variants)
Published
Apr 10, 2019
Tracked Since
Feb 18, 2026