CVE-2019-0064: Junos OS: SRX5000 Series: flowd process crash due to receipt of specific TCP packet
On SRX5000 Series devices, if 'set security zones security-zone <zone> tcp-rst' is configured, the flowd process may crash when a specific TCP packet is received by the device and triggers a new session. The process restarts automatically. However, receipt of a constant stream of these TCP packets may result in an extended Denial of Service (DoS) condition on the device. This issue affects Juniper Networks Junos OS: 18.2R3 on SRX 5000 Series; 18.4R2 on SRX 5000 Series; 19.2R1 on SRX 5000 Series.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0064?
CVE-2019-0064 is categorized as a Medium severity vulnerability.
How do I fix CVE-2019-0064?
To mitigate CVE-2019-0064, upgrade to the recommended Junos version which addresses this issue.
What devices are affected by CVE-2019-0064?
CVE-2019-0064 affects Juniper SRX5000 Series devices running specific versions of Junos OS.
What happens when CVE-2019-0064 is exploited?
Exploitation of CVE-2019-0064 can cause the flowd process to crash and restart automatically under certain conditions.
Is CVE-2019-0064 a remote code execution vulnerability?
CVE-2019-0064 does not classify as a remote code execution vulnerability, but it can lead to service disruption.