First published: Wed Oct 10 2018(Updated: )
Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By continuously sending specific MPLS packets, an attacker can repeatedly crash the RPD process causing a sustained Denial of Service. This issue affects both IPv4 and IPv6. This issue can only be exploited from within the MPLS domain. End-users connected to the CE device cannot cause this crash. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on QFX/EX Series; 14.1X53 versions prior to 14.1X53-D130 on QFabric Series; 15.1F6 versions prior to 15.1F6-S10; 15.1 versions prior to 15.1R4-S9 15.1R7; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D471 15.1X53-D490 on NFX Series; 16.1 versions prior to 16.1R3-S8 16.1R4-S8 16.1R5-S4 16.1R6-S4 16.1R7; 16.1X65 versions prior to 16.1X65-D48; 16.2 versions prior to 16.2R1-S6 16.2R3; 17.1 versions prior to 17.1R1-S7 17.1R2-S6 17.1R3; 17.2 versions prior to 17.2R1-S6 17.2R2-S3 17.2R3; 17.2X75 versions prior to 17.2X75-D100 17.2X75-D42 17.2X75-D91; 17.3 versions prior to 17.3R1-S4 17.3R2-S2 17.3R3; 17.4 versions prior to 17.4R1-S3 17.4R2 . No other Juniper Networks products or platforms are affected by this issue.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | =12.1x46 | |
Juniper Junos | =12.1x46-d10 | |
Juniper Junos | =12.1x46-d15 | |
Juniper Junos | =12.1x46-d20 | |
Juniper Junos | =12.1x46-d25 | |
Juniper Junos | =12.1x46-d30 | |
Juniper Junos | =12.1x46-d35 | |
Juniper Junos | =12.1x46-d40 | |
Juniper Junos | =12.1x46-d45 | |
Juniper Junos | =12.1x46-d50 | |
Juniper Junos | =12.1x46-d55 | |
Juniper SRX1500 | ||
Juniper SRX300 | ||
Juniper SRX320 | ||
Juniper SRX340 | ||
Juniper SRX345 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX5400 | ||
Juniper SRX550 | ||
Juniper SRX5600 | ||
Juniper SRX5800 | ||
Juniper Junos | =12.3 | |
Juniper Junos | =12.3-r1 | |
Juniper Junos | =12.3-r10 | |
Juniper Junos | =12.3-r11 | |
Juniper Junos | =12.3-r2 | |
Juniper Junos | =12.3-r3 | |
Juniper Junos | =12.3-r4 | |
Juniper Junos | =12.3-r5 | |
Juniper Junos | =12.3-r6 | |
Juniper Junos | =12.3-r7 | |
Juniper Junos | =12.3-r8 | |
Juniper Junos | =12.3-r9 | |
Juniper Junos | =12.3x48 | |
Juniper Junos | =12.3x48-d10 | |
Juniper Junos | =12.3x48-d15 | |
Juniper Junos | =12.3x48-d20 | |
Juniper Junos | =12.3x48-d25 | |
Juniper Junos | =12.3x48-d30 | |
Juniper Junos | =12.3x48-d35 | |
Juniper Junos | =12.3x48-d40 | |
Juniper Junos | =12.3x48-d45 | |
Juniper Junos | =12.3x48-d50 | |
Juniper Junos | =12.3x48-d55 | |
Juniper Junos | =12.3x48-d60 | |
Juniper Junos | =12.3x48-d65 | |
Juniper Junos | =12.3x48-d70 | |
Juniper Junos | =14.1x53 | |
Juniper Junos | =14.1x53-d10 | |
Juniper Junos | =14.1x53-d121 | |
Juniper Junos | =14.1x53-d15 | |
Juniper Junos | =14.1x53-d16 | |
Juniper Junos | =14.1x53-d25 | |
Juniper Junos | =14.1x53-d26 | |
Juniper Junos | =14.1x53-d27 | |
Juniper Junos | =14.1x53-d30 | |
Juniper Junos | =14.1x53-d35 | |
Juniper Junos | =14.1x53-d40 | |
Juniper Junos | =14.1x53-d42 | |
Juniper Junos | =14.1x53-d43 | |
Juniper Junos | =14.1x53-d44 | |
Juniper Junos | =14.1x53-d45 | |
Juniper Junos | =14.1x53-d46 | |
Juniper EX2200-C | ||
Juniper EX2200 | ||
Juniper EX2300-24T | ||
Juniper EX2300-C | ||
Juniper EX3200 | ||
Juniper EX3300 | ||
Juniper EX3400 | ||
Juniper EX Series | ||
Juniper EX4300-24T | ||
juniper ex4500-vc | ||
Juniper EX Series | ||
Juniper EX4600 | ||
Juniper EX4650 | ||
Juniper EX Series | ||
Juniper EX8208 | ||
Juniper EX Series | ||
Juniper EX Series | ||
Juniper EX9208 | ||
Juniper EX9214 | ||
Juniper EX9251 | ||
Juniper EX9253 | ||
Juniper OCX1100 | ||
Juniper QFX10002-60C | ||
Juniper QFX10008 | ||
Juniper QFX10016 | ||
Juniper QFX3500 | ||
Juniper QFX3600-I | ||
Juniper QFX5100 | ||
Juniper QFX5110 | ||
Juniper QFX5120 | ||
Juniper QFX5200-48Y | ||
Juniper QFX5210-64C | ||
Juniper Junos | =14.1x53-d20 | |
Juniper Junos | =14.1x53-d47 | |
Juniper QFX3000-G | ||
Juniper QFX3000-M | ||
Juniper Junos | =15.1-f6 | |
Juniper Junos | =15.1 | |
Juniper Junos | =15.1-f3 | |
Juniper Junos | =15.1-f4 | |
Juniper Junos | =15.1-f5 | |
Juniper Junos | =15.1-r1 | |
Juniper Junos | =15.1-r2 | |
Juniper Junos | =15.1-r3 | |
Juniper Junos | =15.1x49 | |
Juniper Junos | =15.1x49-d10 | |
Juniper Junos | =15.1x49-d100 | |
Juniper Junos | =15.1x49-d110 | |
Juniper Junos | =15.1x49-d120 | |
Juniper Junos | =15.1x49-d130 | |
Juniper Junos | =15.1x49-d20 | |
Juniper Junos | =15.1x49-d30 | |
Juniper Junos | =15.1x49-d35 | |
Juniper Junos | =15.1x49-d40 | |
Juniper Junos | =15.1x49-d45 | |
Juniper Junos | =15.1x49-d50 | |
Juniper Junos | =15.1x49-d60 | |
Juniper Junos | =15.1x49-d65 | |
Juniper Junos | =15.1x49-d70 | |
Juniper Junos | =15.1x49-d75 | |
Juniper Junos | =15.1x49-d80 | |
Juniper Junos | =15.1x49-d90 | |
Juniper Junos | =15.1x53 | |
Juniper Junos | =15.1x53-d10 | |
Juniper Junos | =15.1x53-d20 | |
Juniper Junos | =15.1x53-d21 | |
Juniper Junos | =15.1x53-d30 | |
Juniper Junos | =15.1x53-d32 | |
Juniper Junos | =15.1x53-d33 | |
Juniper Junos | =15.1x53-d34 | |
Juniper Junos | =15.1x53-d40 | |
Juniper Junos | =15.1x53-d45 | |
Juniper Junos | =15.1x53-d50 | |
Juniper Junos | =15.1x53-d51 | |
Juniper Junos | =15.1x53-d52 | |
Juniper Junos | =15.1x53-d55 | |
Juniper Junos | =15.1x53-d56 | |
Juniper Junos | =15.1x53-d57 | |
Juniper Junos | =15.1x53-d58 | |
Juniper Junos | =15.1x53-d59 | |
Juniper Junos | =15.1x53-d60 | |
Juniper Junos | =15.1x53-d61 | |
Juniper Junos | =15.1x53-d62 | |
Juniper Junos | =15.1x53-d63 | |
Juniper Junos | =15.1x53-d64 | |
Juniper Junos | =15.1x53-d65 | |
Juniper Junos | =15.1x53-d66 | |
Juniper Junos | =15.1x53-d210 | |
Juniper Junos | =15.1x53-d230 | |
Juniper Junos | =15.1x53-d231 | |
Juniper Junos | =15.1x53-d232 | |
Juniper Junos | =15.1x53-d67 | |
Juniper NFX | ||
Juniper NFX | ||
Juniper Junos | =16.1 | |
Juniper Junos | =16.1-r1 | |
Juniper Junos | =16.1-r2 | |
Juniper Junos | =16.1x65-d30 | |
Juniper Junos | =16.1x65-d35 | |
Juniper Junos | =16.1x65-d40 | |
Juniper Junos | =16.2 | |
Juniper Junos | =16.2-r1 | |
Juniper Junos | =17.1 | |
Juniper Junos | =17.2x75 | |
Juniper Junos | =17.3 | |
Juniper Junos | =17.4 |
The following software releases have been updated to resolve this specific issue: 12.1X46-D77, 12.3R12-S10, 12.3X48-D75, 14.1X53-D130, 14.1X53-D47, 15.1F6-S10, 15.1R4-S9, 15.1R7, 15.1X49-D140, 15.1X53-D233, 15.1X53-D471, 15.1X53-D490, 15.1X53-D59, 15.1X53-D67, 16.1R3-S8, 16.1R4-S8, 16.1R5-S4, 16.1R6-S4, 16.1R7, 16.1X65-D48, 16.2R1-S6, 16.2R2-S6, 16.2R3, 17.1R1-S7, 17.1R2-S6, 17.1R3, 17.2R1-S6, 17.2R2-S3, 17.2R3, 17.2X75-D100, 17.2X75-D42, 17.2X75-D91, 17.3R1-S4, 17.3R2-S2, 17.3R3, 17.4R1-S3, 17.4R2, 18.1R1, 18.2R1, 18.2X75-D5 and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0043 has a CVSS score indicating it's a critical vulnerability that can result in remote code execution and denial of service.
To mitigate CVE-2018-0043, update your Juniper JUNOS software to a version that has patched this vulnerability.
CVE-2018-0043 affects various versions of Juniper JUNOS including 12.1x46 and 12.3, among others.
CVE-2018-0043 is associated with an attack that involves sending specific MPLS packets to crash the routing protocol daemon.
Yes, exploitation of CVE-2018-0043 can lead to remote code execution, potentially compromising sensitive data.