CVE-2019-0038
CVSS V2 Medium 6.1
CVSS V3 Medium 6.5
Description
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gateways. No other products or platforms are affected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D160 on SRX340/SRX345; 17.3 on SRX340/SRX345; 17.4 versions prior to 17.4R2-S3, 17.4R3 on SRX340/SRX345; 18.1 versions prior to 18.1R3-S1 on SRX340/SRX345; 18.2 versions prior to 18.2R2 on SRX340/SRX345; 18.3 versions prior to 18.3R1-S2, 18.3R2 on SRX340/SRX345. This issue does not affect Junos OS releases prior to 15.1X49 on any platform.
Overview
- CVE ID
- CVE-2019-0038
- Assigner
- sirt@juniper.net
- Vulnerability Status
- Analyzed
- Published Version
- 2019-04-10T20:29:00
- Last Modified Date
- 2021-10-25T16:21:47
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:o:juniper:junos:15.1x49:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d150:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d40:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d45:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d50:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d55:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d60:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d65:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d70:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d75:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:15.1x49:d80:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:17.3:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:17.4:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:17.4:r2-s1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:17.4:r2-s2:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:r1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:r2:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:r2-s1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:r2-s2:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.1:r3:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.2:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.2:r1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.3:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.3:r1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.3:r1-s1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:juniper:junos:18.3:r2:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:* | 0 | OR | ||
cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:* | 0 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:A/AC:L/Au:N/C:N/I:N/A:C
- Access Vector
- ADJACENT_NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- NONE
- Integrity Impact
- NONE
- Availability Impact
- COMPLETE
- Base Score
- 6.1
- Severity
- MEDIUM
- Exploitability Score
- 6.5
- Impact Score
- 6.9
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Vector
- ADJACENT_NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- NONE
- Availability Impact
- HIGH
- Base Score
- 6.5
- Base Severity
- MEDIUM
- Exploitability Score
- 2.8
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
https://kb.juniper.net/JSA10927 | Vendor Advisory |
http://www.securityfocus.com/bid/107873 | Third Party Advisory VDB Entry |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2019-0038 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0038 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 06:50:01 | Added to TrackCVE | |||
2022-12-03 19:31:03 | 2019-04-10T20:29Z | 2019-04-10T20:29:00 | CVE Published Date | updated |
2022-12-03 19:31:03 | 2021-10-25T16:21:47 | CVE Modified Date | updated | |
2022-12-03 19:31:03 | Analyzed | Vulnerability Status | updated |