CVE-2018-0006
published 2018-01-10CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber…
PriorityP422medium5.3CVSS 3.0
AVAACHPRNUINSUCNINAH
EPSS
0.67%
47.8th percentile
A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to excessive memory allocation. This issue only affects devices configured for DHCPv4/v6 over AE auto-sensed VLANs, utilized in Broadband Edge (BBE) deployments. Other configurations are unaffected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R6-S2, 15.1R7; 16.1 versions prior to 16.1R5-S1, 16.1R6; 16.2 versions prior to 16.2R2-S2, 16.2R3; 17.1 versions prior to 17.1R2-S5, 17.1R3; 17.2 versions prior to 17.2R2.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 15.1 < 15.1R6-S2, 15.1R7 | 15.1R6-S2, 15.1R7 |
| juniper_networks | junos_os | >= 16.1 < 16.1R5-S1, 16.1R6 | 16.1R5-S1, 16.1R6 |
| juniper_networks | junos_os | >= 16.2 < 16.2R2-S2, 16.2R3 | 16.2R2-S2, 16.2R3 |
| juniper_networks | junos_os | >= 17.1 < 17.1R2-S5, 17.1R3 | 17.1R2-S5, 17.1R3 |
| juniper_networks | junos_os | >= 17.2 < 17.2R2 | 17.2R2 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
vendor_vmware·2018-01-26·CVSS 9.8
CVE-2017-4947 [CRITICAL] vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
VMSA-2018-0006: vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities 2. Relevant Products vRealize Automation (vRA) vSphere Integrated Containers (VIC) VMware AirWatch Console (AWC) 3. Problem Description a. vRealize Automation and vSphere Integrated Containers deserialization vulnerability via Xenon vRealize Automation and vSphere Integrated Containers contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifi
Juniper
CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su
vendor_juniper·2018-01-10·CVSS 6.5
CVE-2018-0006 [MEDIUM] CWE-770 CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su
CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to excessive memory allocation. This issue only affects devices configured for DHCPv4/v6 over AE auto-sensed VLANs, utilized in Broadband Edge (BBE) deployments. Other configurations are unaffected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R6-S2, 15.1R7; 16.1 versions prior to 16.1R5-S1, 16.1R6; 16.2 versions prior to 16.2R2-S2, 16.2R3; 17.1 versions prior to 17.1R2-S5, 17.1R3; 17.2 ver
GHSA
GHSA-f33j-xhh7-r2cj: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su
ghsa_unreviewed·2022-05-13
CVE-2018-0006 [MEDIUM] CWE-770 GHSA-f33j-xhh7-r2cj: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su
A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to excessive memory allocation. This issue only affects devices configured for DHCPv4/v6 over AE auto-sensed VLANs, utilized in Broadband Edge (BBE) deployments. Other configurations are unaffected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R6-S2, 15.1R7; 16.1 versions prior to 16.1R5-S1, 16.1R6; 16.2 versions prior to 16.2R2-S2, 16.2R3; 17.1 versions prior to 17.1R2-S5, 17.1R3; 17.2 versions prior to
No detection rules found.
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
exploitdb·2018-07-13·CVSS 8.8
CVE-2018-0710 [HIGH] QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
---
Core Security - Corelabs Advisory
http://corelabs.coresecurity.com/
QNAP Qcenter Virtual Appliance Multiple Vulnerabilities
1. *Advisory Information*
Title: QNAP Qcenter Virtual Appliance Multiple Vulnerabilities
Advisory ID: CORE-2018-0006
Advisory URL:
http://www.coresecurity.com/advisories/qnap-qcenter-multiple-vulnerabilities
Date published: 2018-07-11
Date of last update: 2018-07-11
Vendors contacted: QNAP
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Information Exposure [CWE-200], Command Injection [CWE-77],
Command Injection [CWE-77], Command Injection [CWE-77],
Command Injection [CWE-77]
Impact: Code execution
Remotely Exploitable: Yes
Locally Exploitable: Yes
CVE Name: CVE-2018-0706, CV
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
exploitdb·2018-02-22·CVSS 6.5
CVE-2018-6230 [MEDIUM] Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
---
Core Security - Corelabs Advisory
http://corelabs.coresecurity.com/
Trend Micro Email Encryption Gateway Multiple Vulnerabilities
1. *Advisory Information*
Title: Trend Micro Email Encryption Gateway Multiple Vulnerabilities
Advisory ID: CORE-2017-0006
Advisory URL:
http://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities
Date published: 2018-02-21
Date of last update: 2018-02-21
Vendors contacted: Trend Micro
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Cleartext Transmission of Sensitive Information [CWE-319],
External Control of File Name or Path [CWE-73], Insufficient
Verification of Data Authenticity [CWE-345], External C
2018-01-10
Published