CVE-2017-2347 Information
Description
A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM is configured. Repeated crashes of the rpd daemon can result in an extended denial of service condition for the device. The affected releases are Junos OS 12.3X48 prior to 12.3X48-D50 12.3X48-D55; 13.3 prior to 13.3R10; 14.1 prior to 14.1R4-S13 14.1R8-S3 14.1R9; 14.1X53 prior to 14.1X53-D42 14.1X53-D50; 14.2 prior to 14.2R4-S8 14.2R7-S6 14.2R8; 15.1 prior to 15.1F2-S14 15.1F5-S7 15.1F6-S4 15.1F7 15.1R4-S7 15.1R5-S1 15.1R6; 15.1X49 prior to 15.1X49-D100; 15.1X53 prior to 15.1X53-D105 15.1X53-D47 15.1X53-D62 15.1X53-D70; 16.1 prior to 16.1R3-S3 16.1R4. No other Juniper Networks products or platforms are affected by this issue.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://www.securityfocus.com/bid/100236 http://www.securitytracker.com/id/1038892 https://kb.juniper.net/JSA10795
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: