CVE-2017-10611
Description
If extended statistics are enabled via set chassis extended-statistics, when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE processing can result in an extended denial of service condition. This issue only affects the following platforms: (1) EX2200, EX3300, XRE200 (2) MX Series routers with MPC7E/8E/9E PFEs installed, and only if extended-statistics are enabled under the [edit chassis] configuration. Affected releases are Juniper Networks Junos OS 14.1 prior to 14.1R8-S5, 14.1R9 on MX Series; 14.1X53 prior to 14.1X53-D46, 14.1X53-D50 on EX2200, EX3300, XRE200; 14.2 prior to 14.2R7-S9, 14.2R8 on MX Series; 15.1 prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S3, 15.1R6 on MX Series; 16.1 prior to 16.1R4-S5, 16.1R5, 16.1R6 on MX Series; 16.1X65 prior to 16.1X65-D45 on EX2200, EX3300, XRE200; 16.2 prior to 16.2R2-S1, 16.2R3 on MX Series; 17.1 prior to 17.1R2-S2, 17.1R3 on MX Series; 17.2 prior to 17.2R1-S3, 17.2R2 on MX Series; 17.2X75 prior to 17.2X75-D50 on MX Series; 17.3 prior to 17.3R1-S1, 17.3R2 on MX Series. No other Juniper Networks products or platforms are affected by this issue.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are fixed in junos 14.1r8-s5 | NCM |
| Vulnerabilities CVE-2017-10611,CVE-2018-0007,CVE-2018-0008 are fixed in junos 14.2r7-s9 | NCM |
| Vulnerabilities CVE-2017-10611,CVE-2017-10618,CVE-2018-0001,CVE-2018-0003 are fixed in junos 15.1f5-s8 | NCM |
| Vulnerabilities CVE-2017-10611 are fixed in junos 16.1r4-s5 | NCM |
| Vulnerabilities CVE-2017-10611 are fixed in junos 16.2r2-s1 | NCM |
| Vulnerabilities CVE-2017-10611,CVE-2018-0003 are fixed in junos 17.1r2-s2 | NCM |
| Vulnerabilities CVE-2017-10611,CVE-2018-0003,CVE-2018-0020 are fixed in junos 17.2r1-s3 | NCM |
| Vulnerabilities CVE-2017-10611 are fixed in junos 17.3r1-s1 | NCM |
| CVE-2017-10611 | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
| PATCH-1704488 | Security Update for junos 9.2r1 |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234