CVE-2019-0007
published 2019-01-15CVE-2019-0007: The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a…
PriorityP357critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
1.73%
75.1th percentile
The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5 on vMX Series.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | mx_series | — | — |
| juniper_networks | junos_os | >= 15.1 < 15.1F5 | 15.1F5 |
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87m6-hv55-49cw: The vMX Series software uses a predictable IP ID Sequence Number
ghsa_unreviewed·2022-05-13
CVE-2019-0007 [CRITICAL] CWE-330 GHSA-87m6-hv55-49cw: The vMX Series software uses a predictable IP ID Sequence Number
The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5 on vMX Series.
VMware
VMware Workstation update addresses a DLL-hijacking issue (CVE-2019-5526)
vendor_vmware·2019-05-14·CVSS 7.8
CVE-2019-5526 [HIGH] VMware Workstation update addresses a DLL-hijacking issue (CVE-2019-5526)
VMSA-2019-0007: VMware Workstation update addresses a DLL-hijacking issue (CVE-2019-5526)
| Advisory Severity | Moderate | Synopsis | VMware Workstation update addresses a DLL-hijacking issue (CVE-2019-5526) | Issue Date | 2019-05-14 | Updated On | 2019-05-14 (Initial Advisory) | CVE(s) | CVE-2019-5526 VMware Workstation Pro / Player (Workstation) 2. IntroductionVMware Workstation update addresses a DLL-hijacking issue:
CVEs: CVE-2019-5526
Affected products: VMware Workstation, Workstation Player, Workstation Pro
Juniper
CVE-2019-0007: The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible
vendor_juniper·2019-01-15·CVSS 9.3
CVE-2019-0007 [CRITICAL] CWE-330 CVE-2019-0007: The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible
CVE-2019-0007: The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5 on vMX Series.
No detection rules found.
No writeups or analysis indexed.
2019-01-15
Published