CVE-2018-0006Allocation of Resources Without Limits or Throttling in Networks Junos OS

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 46.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 13

Description

A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by attempting to process an unbounded number of pending VLAN authentication requests, leading to excessive memory allocation. This issue only affects devices configured for DHCPv4/v6 over AE auto-sensed VLANs, utilized in Broadband Edge (BBE) depl

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages3 packages

CVEListV5juniper_networks/junos_os15.115.1R6-S2, 15.1R7+4
NVDjuniper/junos5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-f33j-xhh7-r2cj: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su2022-05-13

💥Exploits & PoCs

2
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities2018-07-13
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities2018-02-22

📋Vendor Advisories

2
VMware
vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities2018-01-26
Juniper
CVE-2018-0006: A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE su2018-01-10

💬Community

1
Bugzilla
CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock2020-06-18
CVE-2018-0006 — Juniper Networks Junos OS vulnerability | cvebase