ID

VAR-201901-1632


CVE

CVE-2019-0006


TITLE

Juniper Networks Junos OS Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-001692

DESCRIPTION

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. This issue only occurs when the crafted packet it destined to the device. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D47 on EX and QFX Virtual Chassis Platforms; 15.1 versions prior to 15.1R7-S3 all Virtual Chassis Platforms 15.1X53 versions prior to 15.1X53-D50 on EX and QFX Virtual Chassis Platforms. Juniper Networks Junos OS Contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Juniper Junos is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause a denial-of-service condition. Junos OS is a set of operating systems running on it. Security vulnerabilities exist in Junos OS Release 14.1X53, Release 15.1, and 15.1X53 on several Juniper products

Trust: 1.98

sources: NVD: CVE-2019-0006 // JVNDB: JVNDB-2019-001692 // BID: 106666 // VULHUB: VHN-140037

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:15.1x53

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:15.1

Trust: 1.3

vendor:junipermodel:junosscope:eqversion:14.1x53

Trust: 1.3

vendor:junipermodel:junos osscope: - version: -

Trust: 0.8

vendor:junipermodel:junos 15.1x53-d49scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d48scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d47scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d33scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d31scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1r7-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d45scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d44scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d42scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d34scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d28scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d26scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d18scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d16scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d12scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x53-d50scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 15.1r7-s3scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 14.1x53-d47scope:neversion: -

Trust: 0.3

sources: BID: 106666 // JVNDB: JVNDB-2019-001692 // NVD: CVE-2019-0006

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-0006
value: CRITICAL

Trust: 1.0

sirt@juniper.net: CVE-2019-0006
value: CRITICAL

Trust: 1.0

NVD: CVE-2019-0006
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201901-367
value: CRITICAL

Trust: 0.6

VULHUB: VHN-140037
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-0006
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-140037
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sirt@juniper.net: CVE-2019-0006
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

nvd@nist.gov: CVE-2019-0006
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-140037 // JVNDB: JVNDB-2019-001692 // CNNVD: CNNVD-201901-367 // NVD: CVE-2019-0006 // NVD: CVE-2019-0006

PROBLEMTYPE DATA

problemtype:CWE-908

Trust: 1.0

problemtype:CWE-20

Trust: 0.9

sources: VULHUB: VHN-140037 // JVNDB: JVNDB-2019-001692 // NVD: CVE-2019-0006

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201901-367

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201901-367

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-001692

PATCH

title:JSA10906url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10906&actp=METADATA

Trust: 0.8

title:Multiple Juniper product Junos OS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=88532

Trust: 0.6

sources: JVNDB: JVNDB-2019-001692 // CNNVD: CNNVD-201901-367

EXTERNAL IDS

db:NVDid:CVE-2019-0006

Trust: 2.8

db:BIDid:106666

Trust: 2.0

db:JUNIPERid:JSA10906

Trust: 2.0

db:JVNDBid:JVNDB-2019-001692

Trust: 0.8

db:CNNVDid:CNNVD-201901-367

Trust: 0.7

db:VULHUBid:VHN-140037

Trust: 0.1

sources: VULHUB: VHN-140037 // BID: 106666 // JVNDB: JVNDB-2019-001692 // CNNVD: CNNVD-201901-367 // NVD: CVE-2019-0006

REFERENCES

url:http://www.securityfocus.com/bid/106666

Trust: 2.3

url:https://kb.juniper.net/jsa10906

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-0006

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-0006

Trust: 0.8

url:http://www.juniper.net/

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10906&cat=sirt_1&actp=list

Trust: 0.3

sources: VULHUB: VHN-140037 // BID: 106666 // JVNDB: JVNDB-2019-001692 // CNNVD: CNNVD-201901-367 // NVD: CVE-2019-0006

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 106666

SOURCES

db:VULHUBid:VHN-140037
db:BIDid:106666
db:JVNDBid:JVNDB-2019-001692
db:CNNVDid:CNNVD-201901-367
db:NVDid:CVE-2019-0006

LAST UPDATE DATE

2024-08-14T15:18:07.524000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-140037date:2019-10-09T00:00:00
db:BIDid:106666date:2019-01-09T00:00:00
db:JVNDBid:JVNDB-2019-001692date:2019-03-22T00:00:00
db:CNNVDid:CNNVD-201901-367date:2021-10-29T00:00:00
db:NVDid:CVE-2019-0006date:2021-10-28T12:48:13.257

SOURCES RELEASE DATE

db:VULHUBid:VHN-140037date:2019-01-15T00:00:00
db:BIDid:106666date:2019-01-09T00:00:00
db:JVNDBid:JVNDB-2019-001692date:2019-03-22T00:00:00
db:CNNVDid:CNNVD-201901-367date:2019-01-11T00:00:00
db:NVDid:CVE-2019-0006date:2019-01-15T21:29:01.027