Vulnerability Database

290,476

Total vulnerabilities in the database

CVE-2018-0045

Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending the same specific Draft-Rosen MVPN control packet, an attacker can repeatedly crash the RPD process causing a prolonged denial of service. This issue may occur when the Junos OS device is configured for Draft-Rosen multicast virtual private network (MVPN). The VPN is multicast-enabled and configured to use Protocol Independent Multicast (PIM) protocol within the VPN. This issue can only be exploited from the PE device within the MPLS domain which is capable of forwarding IP multicast traffic in core. End-users connected to the CE device cannot cause this crash. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1F6; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 16.1 versions prior to 16.1R4-S9, 16.1R5-S4, 16.1R6-S3, 16.1R7; 16.2 versions prior to 16.2R1-S6, 16.2R2-S6, 16.2R3; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R2-S4, 17.2R3; 17.3 versions prior to 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S3, 17.4R2; 18.1 versions prior to 18.1R2. No other Juniper Networks products or platforms are affected by this issue.

  • Published: Oct 10, 2018
  • Updated: Apr 13, 2023
  • CVE: CVE-2018-0045
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:A/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
juniper / junos 12.1x46-d60 12.1x46-d60.x
juniper / junos 12.1x46-d30 12.1x46-d30.x
juniper / junos 12.1x46-d45 12.1x46-d45.x
juniper / junos 12.1x46-d50 12.1x46-d50.x
juniper / junos 12.1x46-d25 12.1x46-d25.x
juniper / junos 12.1x46 12.1x46.x
juniper / junos 12.1x46-d35 12.1x46-d35.x
juniper / junos 12.1x46-d20 12.1x46-d20.x
juniper / junos 12.1x46-d40 12.1x46-d40.x
juniper / junos 12.1x46-d15 12.1x46-d15.x
juniper / junos 12.1x46-d10 12.1x46-d10.x
juniper / junos 12.1x46-d55 12.1x46-d55.x
juniper / junos 12.3-r11 12.3-r11.x
juniper / junos 12.3-r2 12.3-r2.x
juniper / junos 12.3-r9 12.3-r9.x
juniper / junos 12.3-r4 12.3-r4.x
juniper / junos 12.3-r1 12.3-r1.x
juniper / junos 12.3-r7 12.3-r7.x
juniper / junos 12.3-r6 12.3-r6.x
juniper / junos 12.3-r5 12.3-r5.x
juniper / junos 12.3-r3 12.3-r3.x
juniper / junos 12.3 12.3.x
juniper / junos 12.3-r8 12.3-r8.x
juniper / junos 12.3x48-d10 12.3x48-d10.x
juniper / junos 12.3x48-d15 12.3x48-d15.x
juniper / junos 12.3x48-d35 12.3x48-d35.x
juniper / junos 12.3x48-d50 12.3x48-d50.x
juniper / junos 12.3x48-d30 12.3x48-d30.x
juniper / junos 12.3x48 12.3x48.x
juniper / junos 12.3x48-d25 12.3x48-d25.x
juniper / junos 12.3x48-d45 12.3x48-d45.x
juniper / junos 12.3x48-d55 12.3x48-d55.x
juniper / junos 12.3x48-d40 12.3x48-d40.x
juniper / junos 12.3x48-d60 12.3x48-d60.x
juniper / junos 12.3x48-d65 12.3x48-d65.x
juniper / junos 15.1-r3 15.1-r3.x
juniper / junos 15.1-f4 15.1-f4.x
juniper / junos 15.1-f3 15.1-f3.x
juniper / junos 15.1-r2 15.1-r2.x
juniper / junos 15.1-r1 15.1-r1.x
juniper / junos 15.1-f5 15.1-f5.x
juniper / junos 15.1 15.1.x
juniper / junos 15.1-f6 15.1-f6.x
juniper / junos 15.1x49-d50 15.1x49-d50.x
juniper / junos 15.1x49-d30 15.1x49-d30.x
juniper / junos 15.1x49-d70 15.1x49-d70.x
juniper / junos 15.1x49-d80 15.1x49-d80.x
juniper / junos 15.1x49 15.1x49.x
juniper / junos 15.1x49-d110 15.1x49-d110.x
juniper / junos 15.1x49-d60 15.1x49-d60.x
juniper / junos 15.1x49-d100 15.1x49-d100.x
juniper / junos 15.1x49-d35 15.1x49-d35.x
juniper / junos 15.1x49-d45 15.1x49-d45.x
juniper / junos 15.1x49-d75 15.1x49-d75.x
juniper / junos 15.1x49-d65 15.1x49-d65.x
juniper / junos 15.1x49-d90 15.1x49-d90.x
juniper / junos 15.1x49-d40 15.1x49-d40.x
juniper / junos 15.1x49-d20 15.1x49-d20.x
juniper / junos 15.1x49-d10 15.1x49-d10.x
juniper / junos 15.1x49-d55 15.1x49-d55.x
juniper / junos 15.1x49-d120 15.1x49-d120.x
juniper / junos 15.1x49-d130 15.1x49-d130.x
juniper / junos 15.1x53-d40 15.1x53-d40.x
juniper / junos 15.1x53-d20 15.1x53-d20.x
juniper / junos 15.1x53-d30 15.1x53-d30.x
juniper / junos 15.1x53 15.1x53.x
juniper / junos 15.1x53-d33 15.1x53-d33.x
juniper / junos 15.1x53-d25 15.1x53-d25.x
juniper / junos 15.1x53-d32 15.1x53-d32.x
juniper / junos 15.1x53-d57 15.1x53-d57.x
juniper / junos 15.1x53-d34 15.1x53-d34.x
juniper / junos 15.1x53-d21 15.1x53-d21.x
juniper / junos 15.1x53-d45 15.1x53-d45.x
juniper / junos 15.1x53-d50 15.1x53-d50.x
juniper / junos 15.1x53-d51 15.1x53-d51.x
juniper / junos 15.1x53-d52 15.1x53-d52.x
juniper / junos 15.1x53-d55 15.1x53-d55.x
juniper / junos 15.1x53-d58 15.1x53-d58.x
juniper / junos 15.1x53-d62 15.1x53-d62.x
juniper / junos 15.1x53-d63 15.1x53-d63.x
juniper / junos 15.1x53-d64 15.1x53-d64.x
juniper / junos 15.1x53-d60 15.1x53-d60.x
juniper / junos 15.1x53-d61 15.1x53-d61.x
juniper / junos 15.1x53-d65 15.1x53-d65.x
juniper / junos 15.1x53-d66 15.1x53-d66.x
juniper / junos 15.1x53-d210 15.1x53-d210.x
juniper / junos 15.1x53-d230 15.1x53-d230.x
juniper / junos 15.1x53-d231 15.1x53-d231.x
juniper / junos 15.1x53-d232 15.1x53-d232.x
juniper / junos 15.1x53-d490 15.1x53-d490.x
juniper / junos 16.1-r1 16.1-r1.x
juniper / junos 16.1 16.1.x
juniper / junos 16.1-r3 16.1-r3.x
juniper / junos 16.1-r2 16.1-r2.x
juniper / junos 16.2 16.2.x
juniper / junos 16.2-r1 16.2-r1.x
juniper / junos 17.1 17.1.x
juniper / junos 17.2 17.2.x
juniper / junos 17.2-r1 17.2-r1.x
juniper / junos 17.2-r2 17.2-r2.x
juniper / junos 17.3-r1 17.3-r1.x
juniper / junos 17.3 17.3.x
juniper / junos 17.4 17.4.x
juniper / junos 18.1-r1 18.1-r1.x
juniper / junos 18.1 18.1.x