Vulnerability Description
A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. Affected releases are Juniper Networks Junos OS on QFX 5000 series, EX4300, EX4600 are: 14.1X53; 15.1X53 versions prior to 15.1X53-D235; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3-S2, 17.3R4; 17.4 versions prior to 17.4R2-S1, 17.4R3; 18.1 versions prior to 18.1R3-S1, 18.1R4; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | >= 15.1x53, < 15.1x53-d235 |
| Juniper | Ex4300 | - |
| Juniper | Ex4300M | - |
| Juniper | Ex4600 | - |
| Juniper | Ex4650 | - |
| Juniper | Qfx5100 | - |
| Juniper | Qfx5110 | - |
| Juniper | Qfx5120 | - |
| Juniper | Qfx5200-32C | - |
| Juniper | Qfx5200-48Y | - |
| Juniper | Qfx5210-64C | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107897Third Party AdvisoryVDB Entry
- https://kb.juniper.net/JSA10930Vendor Advisory
- http://www.securityfocus.com/bid/107897Third Party AdvisoryVDB Entry
- https://kb.juniper.net/JSA10930Vendor Advisory
FAQ
What is CVE-2019-0008?
CVE-2019-0008 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices....
How severe is CVE-2019-0008?
CVE-2019-0008 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-0008?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Ex4300, Juniper Ex4300M, Juniper Ex4600, Juniper Ex4650.