CVE-2019-0052 — Improper Resource Shutdown or Release in Networks Junos OS
CWE-404 — Improper Resource Shutdown or ReleaseCWE-436 — Interpretation Conflict5 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 42.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11
Latest updateMay 24
Description
The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterpreted as a regular TCP packet which causes the processor to crash. This issue affects all SRX Series platforms that support URL-Filtering and have web-filtering enabled. Affected releases are Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D85 on SRX Series; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 17.3 versio…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-q7jm-8335-rc9c: The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet↗2022-05-24
📋Vendor Advisories
1Juniper▶
CVE-2019-0052: The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterpr↗2019-07-11