Vulnerability Description
A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the mib2d process to crash resulting in a denial of service condition (DoS) for the SNMP subsystem. While a mib2d process crash can disrupt the network monitoring via SNMP, it does not impact routing, switching or firewall functionalities. SNMP is disabled by default on devices running Junos OS. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D76; 12.3 versions prior to 12.3R12-S7, 12.3R13; 12.3X48 versions prior to 12.3X48-D65; 14.1 versions prior to 14.1R9; 14.1X53 versions prior to 14.1X53-D130; 15.1 versions prior to 15.1F2-S20, 15.1F6-S10, 15.1R7; 15.1X49 versions prior to 15.1X49-D130; 15.1X53 versions prior to 15.1X53-D233, 15.1X53-D471, 15.1X53-D472, 15.1X53-D58, 15.1X53-D66; 16.1 versions prior to 16.1R5-S3, 16.1R7; 16.1X65 versions prior to 16.1X65-D47; 16.1X70 versions prior to 16.1X70-D10; 16.2 versions prior to 16.2R1-S6, 16.2R2-S5, 16.2R3; 17.1 versions prior to 17.1R2-S6, 17.1R3;
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 15.1x49 |
| Juniper | Ex4300 | - |
| Juniper | Ex4600 | - |
| Juniper | Qfx5100 | - |
| Juniper | Ex2300 | - |
| Juniper | Ex3400 | - |
| Juniper | Qfx5110 | - |
| Juniper | Qfx5200 | - |
| Juniper | Nfx150 | - |
| Juniper | Nfx250 | - |
| Juniper | Qfx10 | - |
| Juniper | Qfabric | - |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1040787Third Party AdvisoryVDB Entry
- https://kb.juniper.net/JSA10847MitigationPatchVendor Advisory
- http://www.securitytracker.com/id/1040787Third Party AdvisoryVDB Entry
- https://kb.juniper.net/JSA10847MitigationPatchVendor Advisory
FAQ
What is CVE-2018-0019?
CVE-2018-0019 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the mib2d process to crash resulting in a denial of service condition (DoS) for the S...
How severe is CVE-2018-0019?
CVE-2018-0019 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0019?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Ex4300, Juniper Ex4600, Juniper Qfx5100, Juniper Ex2300.