cbcvebase.
CVE-2019-0019
published 2019-04-10

CVE-2019-0019: When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.14%
63.0th percentile
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4, 18.1R4; 18.2 versions prior to 18.2R2-S2, 18.2R2-S3, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue does not affect Junos releases prior to 16.1R1.

Affected

22 ranges
VendorProductVersion rangeFixed in
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniper_networksjunos_os>= 16.1 < 16.1R7-S4, 16.1R7-S516.1R7-S4, 16.1R7-S5
juniper_networksjunos_os>= 16.2 < 16.2R2-S9, 16.2R316.2R2-S9, 16.2R3
juniper_networksjunos_os>= 17.1 < 17.1R317.1R3
juniper_networksjunos_os>= 17.2 < 17.2R3-S117.2R3-S1
juniper_networksjunos_os>= 17.3 < 17.3R3-S3, 17.3R3-S4, 17.3R417.3R3-S3, 17.3R3-S4, 17.3R4
juniper_networksjunos_os>= 17.4 < 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R317.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3
juniper_networksjunos_os>= 18.1 < 18.1R2-S4, 18.1R3-S4, 18.1R418.1R2-S4, 18.1R3-S4, 18.1R4
juniper_networksjunos_os>= 18.2 < 18.2R2-S2, 18.2R2-S3, 18.2R318.2R2-S2, 18.2R2-S3, 18.2R3
juniper_networksjunos_os>= 18.2X75 < 18.2X75-D4018.2X75-D40
juniper_networksjunos_os>= 18.3 < 18.3R1-S3, 18.3R218.3R1-S3, 18.3R2
juniper_networksjunos_os>= 18.4 < 18.4R1-S2, 18.4R218.4R1-S2, 18.4R2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.