CVE-2019-0068

Description

The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packets. By continuously sending the specific multicast packets, an attacker can repeatedly crash the flowd process causing a sustained Denial of Service. This issue affects Juniper Networks Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D90; 15.1X49 versions prior to 15.1X49-D180; 17.3 versions; 17.4 versions prior to 17.4R2-S5, 17.4R3; 18.1 versions prior to 18.1R3-S6; 18.2 versions prior to 18.2R2-S4, 18.2R3; 18.3 versions prior to 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S1, 19.1R2.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.277

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-0068,CVE-2020-1600,CVE-2020-1657 are fixed in junos 12.3X48-D90NCM
Vulnerabilities CVE-2019-0051,CVE-2019-0068,CVE-2019-0073 are fixed in junos 15.1x49-d180NCM
Vulnerabilities CVE-2019-0048,CVE-2019-0063,CVE-2019-0068,CVE-2020-1603 are fixed in junos 17.4r2-s5NCM
Vulnerabilities CVE-2019-0052,CVE-2019-0063,CVE-2019-0068,CVE-2020-1608 are fixed in junos 18.1r3-s6NCM
Vulnerabilities CVE-2019-0063,CVE-2019-0068 are fixed in junos 18.2r2-s4NCM
Vulnerabilities CVE-2019-0068 are fixed in junos 18.3r2-s1NCM
Multiple Vulnerabilities are fixed in junos 18.4R2NCM
Vulnerabilities CVE-2019-0068 are fixed in junos 19.1r1-s1NCM
Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2019-0068)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234