CRITICAL · 9.3

CVE-2019-0007

The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of pr...

Vulnerability Description

The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5 on vMX Series.

CVSS Score

9.3

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
JuniperJunos15.1
JuniperMx10-
JuniperMx10003-
JuniperMx10008-
JuniperMx104-
JuniperMx150-
JuniperMx2008-
JuniperMx2010-
JuniperMx2020-
JuniperMx204-
JuniperMx240-
JuniperMx40-
JuniperMx480-
JuniperMx5-
JuniperMx80-
JuniperMx960-
JuniperVmx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0007?

CVE-2019-0007 is a vulnerability with a CVSS score of 9.3 (CRITICAL). The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of pr...

How severe is CVE-2019-0007?

CVE-2019-0007 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-0007?

Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Mx10, Juniper Mx10003, Juniper Mx10008, Juniper Mx104.