CVE-2018-0030Uncontrolled Resource Consumption in Networks Junos OS

Severity
7.5HIGHNVD
EPSS
0.5%
top 33.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart. By continuously sending specific MPLS packets, an attacker can repeatedly crash the line cards or PTX1K causing a sustained Denial of Service. Affected releases are Juniper Networks Junos OS with MPC7/8/9 or PTX-FPC3 (FPC-P1, FPC-P2) installed and PTX1K: 15.1F versions prior to 15.1F6-S10; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 16.1 versions prior to 16.1R3-S8,

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5juniper_networks/junos_os15.1F15.1F6-S10+9
NVDjuniper/junos9 versions+8

🔴Vulnerability Details

1
GHSA
GHSA-jr7j-5wrw-qxv3: Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart2022-05-13

💥Exploits & PoCs

1
Exploit-DB
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)2018-09-06

📋Vendor Advisories

2
VMware
VMware Workstation and Fusion updates address an integer overflow issue.2018-11-22
Juniper
CVE-2018-0030: Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart. By continuously sending spec2018-07-11
CVE-2018-0030 — Uncontrolled Resource Consumption | cvebase