CVE Feed

    Dashboard / CVE / CVE-2019-0066

    CVE-2019-0066

    An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of Juniper Networks Junos OS allows attacker to cause a Denial of Service (DoS) condition and core the routing protocol daemon (rpd) process when a specific malformed IPv4 packet is received by the device running BGP. This malformed packet can be crafted and sent to a victim device including when forwarded directly through a device receiving such a malformed packet, but not if the malformed packet is first de-encapsulated from an encapsulated format by a receiving device. Continued receipt of the malformed packet will result in a sustained Denial of Service condition. This issue affects: Juniper Networks Junos OS 15.1 versions prior to 15.1F6-S12, 15.1R7-S2; 15.1X49 versions prior to 15.1X49-D150 on SRX Series; 15.1X53 versions prior to 15.1X53-D68, 15.1X53-D235, 15.1X53-D495, 15.1X53-D590; 16.1 versions prior to 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S2; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S9, 17.1R3; 17.2 versions prior to 17.2R1-S7, 17.2R2-S6, 17.2R3; 17.3 versions prior to 17.3R2-S4, 17.3R3.

    Published:Oct 9, 2019
    Last Modified:Nov 21, 2024
    EPS:Oct 9, 2019
    EPSS Score:0.00467
    CVSS Score:7.5

    Affected Products

    Vendor
    Juniper
    Product
    Csrx
    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper
    Product
    Srx100
    Vendor
    Juniper
    Product
    Srx110
    Vendor
    Juniper
    Product
    Srx1400
    Vendor
    Juniper
    Product
    Srx1500
    Vendor
    Juniper
    Product
    Srx210
    Vendor
    Juniper
    Product
    Srx220
    Vendor
    Juniper
    Product
    Srx240
    Vendor
    Juniper
    Product
    Srx300
    Vendor
    Juniper
    Product
    Srx320
    Vendor
    Juniper
    Product
    Srx340
    Vendor
    Juniper
    Product
    Srx3400
    Vendor
    Juniper
    Product
    Srx345
    Vendor
    Juniper
    Product
    Srx3600
    Vendor
    Juniper
    Product
    Srx4100
    Vendor
    Juniper
    Product
    Srx4200
    Vendor
    Juniper
    Product
    Srx4600
    Vendor
    Juniper
    Product
    Srx5400
    Vendor
    Juniper
    Product
    Srx550
    Vendor
    Juniper
    Product
    Srx550 Hm
    Vendor
    Juniper
    Product
    Srx5600
    Vendor
    Juniper
    Product
    Srx5800
    Vendor
    Juniper
    Product
    Srx650
    Vendor
    Juniper
    Product
    Vsrx

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High