CVE-2019-0002Incomplete Filtering of Multiple Instances of Special Elements in Networks Junos OS

Severity
9.8CRITICALNVD
EPSS
0.2%
top 54.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 13

Description

On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take effect. When this issue occurs, the output of the command: show pfe filter hw summary will not show the entry for: RACL group Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions prior to 15.1X53-D590; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2. This issue affect both IPv4 and IPv6 firewall filter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5juniper_networks/junos_os15.1X5315.1X53-D590+2
NVDjuniper/junos15.1x53, 18.1, 18.2+2

🔴Vulnerability Details

1
GHSA
GHSA-9v62-432v-6vc6: On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take e2022-05-13

💥Exploits & PoCs

1
Exploit-DB
Publisure Hybrid - Multiple Vulnerabilities2019-09-06

📋Vendor Advisories

1
Juniper
CVE-2019-0002: On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take e2019-01-15

📄Research Papers

1
arXiv
Vulnerability Forecasting: In theory and practice2020-12-07

💬Community

19
Bugzilla
CVE-2019-18823 htcondor: Incorrect access control in condor_startd2020-04-27
Bugzilla
CVE-2019-8558 webkitgtk: malicious crafted web content leads to arbitrary code execution2019-06-11
Bugzilla
CVE-2019-8523 webkitgtk: malicious web content leads to arbitrary code execution2019-06-11
Bugzilla
CVE-2019-8518 webkitgtk: malicious web content leads to arbitrary code execution2019-06-11
Bugzilla
CVE-2019-8503 webkitgtk: logic issue leads to code execution2019-06-11
CVE-2019-0002 — Juniper Networks Junos OS vulnerability | cvebase