CVE-2019-0063: Junos OS: MX Series: jdhcpd crash when receiving a specific crafted DHCP response message
When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 enabled, jdhcpd might crash when receiving a specific crafted DHCP response message on a subscriber interface. The daemon automatically restarts without intervention, but continuous receipt of specific crafted DHCP messages will repeatedly crash jdhcpd, leading to an extended Denial of Service (DoS) condition. This issue only affects systems configured with DHCPv6 enabled. DHCPv4 is unaffected by this issue. This issue affects Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S5 on MX Series; 16.1 versions prior to 16.1R7-S5 on MX Series; 16.2 versions prior to 16.2R2-S10 on MX Series; 17.1 versions prior to 17.1R3-S1 on MX Series; 17.2 versions prior to 17.2R3-S2 on MX Series; 17.3 versions prior to 17.3R3-S6 on MX Series; 17.4 versions prior to 17.4R2-S5, 17.4R3 on MX Series; 18.1 versions prior to 18.1R3-S6 on MX Series; 18.2 versions prior to 18.2R2-S4, 18.2R3 on MX Series; 18.2X75 versions prior to 18.2X75-D50 on MX Series; 18.3 versions prior to 18.3R1-S5, 18.3R3 on MX Series; 18.4 versions prior to 18.4R2 on MX Series; 19.1 versions prior to 19.1R1-S2, 19.1R2 on MX Series.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0063?
The severity of CVE-2019-0063 is classified as high due to the potential impact on the system's stability.
How do I fix CVE-2019-0063?
To fix CVE-2019-0063, upgrade your Juniper JUNOS software to the latest version recommended by the vendor.
Which versions of the software are affected by CVE-2019-0063?
CVE-2019-0063 affects specific versions of Juniper JUNOS including 15.1-a1, 15.1-f1, and various others up to 17.4.
What happens when CVE-2019-0063 is exploited?
Exploitation of CVE-2019-0063 can cause the jdhcpd daemon to crash, requiring a restart to recover.
Is there a workaround for CVE-2019-0063 before applying the fix?
While a permanent fix is recommended through an upgrade, temporarily disabling DHCPv6 may serve as a workaround.