CVE-2019-0006
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. This issue only occurs when the crafted packet it destined to the device. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D47 on EX and QFX Virtual Chassis Platforms; 15.1 versions prior to 15.1R7-S3 all Virtual Chassis Platforms 15.1X53 versions prior to 15.1X53-D50 on EX and QFX Virtual Chassis Platforms.
Published:Jan 15, 2019
Last Modified:Nov 21, 2024
EPS:Jan 15, 2019
EPSS Score:0.05923
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Ex2200
Juniper
Ex2200
Vendor
Juniper
Product
Ex2200-c
Juniper
Ex2200-c
Vendor
Juniper
Product
Ex2300
Juniper
Ex2300
Vendor
Juniper
Product
Ex2300-c
Juniper
Ex2300-c
Vendor
Juniper
Product
Ex3300
Juniper
Ex3300
Vendor
Juniper
Product
Ex3400
Juniper
Ex3400
Vendor
Juniper
Product
Ex4200
Juniper
Ex4200
Vendor
Juniper
Product
Ex4300
Juniper
Ex4300
Vendor
Juniper
Product
Ex4500
Juniper
Ex4500
Vendor
Juniper
Product
Ex4550
Juniper
Ex4550
Vendor
Juniper
Product
Ex4600
Juniper
Ex4600
Vendor
Juniper
Product
Ex4650
Juniper
Ex4650
Vendor
Juniper
Product
Ex6210
Juniper
Ex6210
Vendor
Juniper
Product
Ex8208
Juniper
Ex8208
Vendor
Juniper
Product
Ex8216
Juniper
Ex8216
Vendor
Juniper
Product
Ex9204
Juniper
Ex9204
Vendor
Juniper
Product
Ex9208
Juniper
Ex9208
Vendor
Juniper
Product
Ex9214
Juniper
Ex9214
Vendor
Juniper
Product
Ex9251
Juniper
Ex9251
Vendor
Juniper
Product
Ex9253
Juniper
Ex9253
Vendor
Juniper
Product
Junos
Juniper
Junos
Vendor
Juniper
Product
Qfx10002
Juniper
Qfx10002
Vendor
Juniper
Product
Qfx10008
Juniper
Qfx10008
Vendor
Juniper
Product
Qfx10016
Juniper
Qfx10016
Vendor
Juniper
Product
Qfx3500
Juniper
Qfx3500
Vendor
Juniper
Product
Qfx3600
Juniper
Qfx3600
Vendor
Juniper
Product
Qfx5100
Juniper
Qfx5100
Vendor
Juniper
Product
Qfx5110
Juniper
Qfx5110
Vendor
Juniper
Product
Qfx5120
Juniper
Qfx5120
Vendor
Juniper
Product
Qfx5200
Juniper
Qfx5200
Vendor
Juniper
Product
Qfx5210
Juniper
Qfx5210
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
