CVE-2019-0068: Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packets. By continuously sending the specific multicast packets, an attacker can repeatedly crash the flowd process causing a sustained Denial of Service. This issue affects Juniper Networks Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D90; 15.1X49 versions prior to 15.1X49-D180; 17.3 versions; 17.4 versions prior to 17.4R2-S5, 17.4R3; 18.1 versions prior to 18.1R3-S6; 18.2 versions prior to 18.2R2-S4, 18.2R3; 18.3 versions prior to 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S1, 19.1R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0068?
CVE-2019-0068 is classified as a high severity vulnerability due to its potential to cause a sustained Denial of Service.
How do I fix CVE-2019-0068?
To remediate CVE-2019-0068, you should apply the appropriate patches or updates provided by Juniper for affected JUNOS versions.
What products are affected by CVE-2019-0068?
CVE-2019-0068 affects various versions of Juniper JUNOS including 12.3x48 and 15.1x49, among others.
What is the impact of CVE-2019-0068?
The impact of CVE-2019-0068 is that attackers can exploit this vulnerability to repeatedly crash the SRX flowd process, leading to a denial of service.
Is CVE-2019-0068 exploitable remotely?
Yes, CVE-2019-0068 can be exploited remotely by sending specific multicast packets to the affected devices.