Vulnerability Description
A vulnerability in the SIP ALG packet processing service of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specific types of valid SIP traffic to the device. In this case, the flowd process crashes and generates a core dump while processing SIP ALG traffic. Continued receipt of these valid SIP packets will result in a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D61, 12.3X48-D65 on SRX Series; 15.1X49 versions prior to 15.1X49-D130 on SRX Series; 17.3 versions prior to 17.3R3 on SRX Series; 17.4 versions prior to 17.4R2 on SRX Series.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 12.3x48 |
| Juniper | Csrx | - |
| Juniper | Srx100 | - |
| Juniper | Srx110 | - |
| Juniper | Srx1400 | - |
| Juniper | Srx1500 | - |
| Juniper | Srx210 | - |
| Juniper | Srx220 | - |
| Juniper | Srx240 | - |
| Juniper | Srx300 | - |
| Juniper | Srx320 | - |
| Juniper | Srx340 | - |
| Juniper | Srx3400 | - |
| Juniper | Srx345 | - |
| Juniper | Srx3600 | - |
| Juniper | Srx4100 | - |
| Juniper | Srx4200 | - |
| Juniper | Srx4600 | - |
| Juniper | Srx5400 | - |
| Juniper | Srx550 | - |
Related Weaknesses (CWE)
References
- https://kb.juniper.net/JSA10953Vendor Advisory
- https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-sip-Vendor Advisory
- https://kb.juniper.net/JSA10953Vendor Advisory
- https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-sip-Vendor Advisory
FAQ
What is CVE-2019-0055?
CVE-2019-0055 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in the SIP ALG packet processing service of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specific types of valid SIP traffic...
How severe is CVE-2019-0055?
CVE-2019-0055 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0055?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Csrx, Juniper Srx100, Juniper Srx110, Juniper Srx1400.