CVE-2019-0049Improper Resource Shutdown or Release in Networks Junos OS

Severity
7.5HIGHNVD
EPSS
0.5%
top 34.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 24

Description

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a certain sequence of BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process to crash and restart. Repeated crashes of the RPD process can cause prolonged Denial of Service (DoS). Graceful restart helper mode for BGP is enabled by default. No other Juniper Networks products or platforms are affect

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5juniper_networks/junos_os11 versions+10
NVDjuniper/junos11 versions+10

Patches

🔴Vulnerability Details

1
GHSA
GHSA-9638-3mrm-pfhx: On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a certain sequence of BGP session re2022-05-24

💥Exploits & PoCs

1
Exploit-DB
Codiad 2.8.4 - Remote Code Execution (Authenticated) (2)2021-05-24

📋Vendor Advisories

1
Juniper
CVE-2019-0049: On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a certain sequence of BGP session re2019-07-11
CVE-2019-0049 — Improper Resource Shutdown or Release | cvebase