CVE-2019-0033
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
10/04/2019
Last modified:
12/04/2019
Description
A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a Denial of Service (DoS). This issue affects only IPv4. Affected releases are Juniper Networks Junos OS: 12.1X46 versions above and including 12.1X46-D25 prior to 12.1X46-D71, 12.1X46-D73 on SRX Series; 12.3X48 versions prior to 12.3X48-D50 on SRX Series; 15.1X49 versions prior to 15.1X49-D75 on SRX Series.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 12.1x46 (including) | 12.1x46-d10 (including) |
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 12.1x46-d25 (including) | 12.1x46-d71 (excluding) |
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 12.3x48 (including) | 12.3x48-d50 (excluding) |
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 15.1x49 (including) | 15.1x49-d75 (excluding) |
| cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx3400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx3600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx550:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



