CVE-2019-0019
published 2019-04-10CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.14%
63.0th percentile
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4, 18.1R4; 18.2 versions prior to 18.2R2-S2, 18.2R2-S3, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue does not affect Junos releases prior to 16.1R1.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 16.1 < 16.1R7-S4, 16.1R7-S5 | 16.1R7-S4, 16.1R7-S5 |
| juniper_networks | junos_os | >= 16.2 < 16.2R2-S9, 16.2R3 | 16.2R2-S9, 16.2R3 |
| juniper_networks | junos_os | >= 17.1 < 17.1R3 | 17.1R3 |
| juniper_networks | junos_os | >= 17.2 < 17.2R3-S1 | 17.2R3-S1 |
| juniper_networks | junos_os | >= 17.3 < 17.3R3-S3, 17.3R3-S4, 17.3R4 | 17.3R3-S3, 17.3R3-S4, 17.3R4 |
| juniper_networks | junos_os | >= 17.4 < 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3 | 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3 |
| juniper_networks | junos_os | >= 18.1 < 18.1R2-S4, 18.1R3-S4, 18.1R4 | 18.1R2-S4, 18.1R3-S4, 18.1R4 |
| juniper_networks | junos_os | >= 18.2 < 18.2R2-S2, 18.2R2-S3, 18.2R3 | 18.2R2-S2, 18.2R2-S3, 18.2R3 |
| juniper_networks | junos_os | >= 18.2X75 < 18.2X75-D40 | 18.2X75-D40 |
| juniper_networks | junos_os | >= 18.3 < 18.3R1-S3, 18.3R2 | 18.3R1-S3, 18.3R2 |
| juniper_networks | junos_os | >= 18.4 < 18.4R1-S2, 18.4R2 | 18.4R1-S2, 18.4R2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mpq6-qrw3-g58q: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart
ghsa_unreviewed·2022-05-13
CVE-2019-0019 [HIGH] GHSA-mpq6-qrw3-g58q: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4, 18.1R4; 18.2 versions prior to 18.2R2-S2, 18.2R2-S3, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue does not affect
VMware
VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
vendor_vmware·2019-10-24·CVSS 6.5
CVE-2019-5536 [MEDIUM] VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
VMSA-2019-0019: VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
| Advisory Severity | Moderate | Synopsis | VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536) | Issue Date | 2019-10-24 | Updated On | 2019-10-24 (Initial Advisory) | CVE(s) | CVE-2019-5536 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5536
Affected products: Fusion Pro, VMware ESXi, VMware Fusion, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
Juniper
CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd resta
vendor_juniper·2019-04-10·CVSS 7.5
CVE-2019-0019 [HIGH] CWE-404 CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd resta
CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4, 18.1R4; 18.2 versions prior to 18.2R2-S2, 18.2R2-S3, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-10
Published