CVE-2017-10608 — Uncontrolled Resource Consumption in Networks Junos OS
Severity
7.5HIGHNVD
EPSS
0.4%
top 40.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 13
Latest updateMay 13
Description
Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated denial of service against the target. Repeated traffic in a cluster may cause repeated flip-flop failure operations or full failure to the flowd daemon halting traffic on all nodes. Only IPv6 traffic is affected by this issue. IPv4 traffic i…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
▶CVEListV5juniper_networks/junos_os12.1X46 prior to 12.1X46-D55, 12.3X48 prior to 12.3X48-D32, 12.3X48-D35, 15.1X49 prior to 15.1X49-D60+2
🔴Vulnerability Details
1GHSA▶
GHSA-g49f-pqv2-64w5: Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs↗2022-05-13
📋Vendor Advisories
1Juniper▶
CVE-2017-10608: Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. Th↗2017-10-13