CVE-2017-2304
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'
Published:May 30, 2017
Last Modified:Apr 20, 2025
EPS:May 30, 2017
EPSS Score:0.00961
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Ex4300
Juniper
Ex4300
Vendor
Juniper
Product
Ex4600
Juniper
Ex4600
Vendor
Juniper
Product
Junos
Juniper
Junos
Vendor
Juniper
Product
Qfx3500
Juniper
Qfx3500
Vendor
Juniper
Product
Qfx3600
Juniper
Qfx3600
Vendor
Juniper
Product
Qfx5100
Juniper
Qfx5100
Vendor
Juniper
Product
Qfx5200
Juniper
Qfx5200
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
