218 lines
7.1 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2018-0032",
"sourceIdentifier": "sirt@juniper.net",
"published": "2018-07-11T18:29:00.573",
"lastModified": "2024-11-21T03:37:23.983",
2023-04-24 12:24:31 +02:00
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can result in an extended denial of service condition for the device. This issue only affects the specific versions of Junos OS listed within this advisory. Earlier releases are unaffected by this vulnerability. This crafted BGP UPDATE does not propagate to other BGP peers. Affected releases are Juniper Networks Junos OS: 16.1X65 versions prior to 16.1X65-D47; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D110; 17.3 versions prior to 17.3R1-S4, 17.3R2; 17.4 versions prior to 17.4R1-S3, 17.4R2."
},
{
"lang": "es",
"value": "La recepci\u00f3n de un BGP UPDATE manipulado puede conducir al cierre inesperado y reinicio de un demonio de proceso de enrutamiento (RPD). La recepci\u00f3n repetida del mismo BGP UPDATE manipulado puede resultar en una condici\u00f3n de denegaci\u00f3n de servicio (DoS) extendida para los dispositivos. Este problema solo afecta a las versiones espec\u00edficas de Junos OS listadas en este advisory. Las versiones anteriores no se han visto afectadas por esta vulnerabilidad. Este BGP UPDATE manipulado no se propaga a otros peers BGP. Las versiones afectadas son Juniper Networks Junos OS: 16.1X65 en versiones anteriores a 16.1X65-D47; 17.2X75 en versiones anteriores a 17.2X75-D91, 17.2X75-D110; 17.3 en versiones anteriores a 17.3R1-S4, 17.3R2; 17.4 en versiones anteriores a 17.4R1-S3 y 17.4R2."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "sirt@juniper.net",
"type": "Secondary",
2023-04-24 12:24:31 +02:00
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH",
2023-04-24 12:24:31 +02:00
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
2023-04-24 12:24:31 +02:00
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
},
{
"source": "nvd@nist.gov",
"type": "Primary",
2023-04-24 12:24:31 +02:00
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH",
2023-04-24 12:24:31 +02:00
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
2023-04-24 12:24:31 +02:00
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"baseScore": 5.0,
2023-04-24 12:24:31 +02:00
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL"
2023-04-24 12:24:31 +02:00
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:*:*:*:*:*:*:*",
"matchCriteriaId": "CA096D02-3E65-4D84-AB38-DE6DC7270097"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d30:*:*:*:*:*:*",
"matchCriteriaId": "2A347C15-3ABC-4B11-A9BB-5DF1C73538EE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d35:*:*:*:*:*:*",
"matchCriteriaId": "EBCD72E3-22CE-4E9E-9CC5-686C4B163116"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d40:*:*:*:*:*:*",
"matchCriteriaId": "46A11513-B901-4E12-8AA7-54D4794595D2"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:17.2x75:*:*:*:*:*:*:*",
"matchCriteriaId": "191A3F26-3C6E-4B5A-9D40-E6ABC2BFA7AF"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:17.3:*:*:*:*:*:*:*",
"matchCriteriaId": "0F69A0E5-B61B-405D-B501-9CB306651CEA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:17.3:r1:*:*:*:*:*:*",
"matchCriteriaId": "38A40E03-F915-4888-87B0-5950F75F097D"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:17.4:*:*:*:*:*:*:*",
"matchCriteriaId": "974B6128-ABD2-4D9C-87A1-5F1740DDCB95"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:juniper:junos:17.4:r1:*:*:*:*:*:*",
"matchCriteriaId": "988D317A-0646-491F-9B97-853E8E208276"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securitytracker.com/id/1041337",
"source": "sirt@juniper.net",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://kb.juniper.net/JSA10866",
"source": "sirt@juniper.net",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securitytracker.com/id/1041337",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://kb.juniper.net/JSA10866",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}