VulnerabilityModified
CVE-2017-2304
This issue is also known as 'Etherleak'
HIGH 7.5EPSS 1.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- juniper/junos
- Source
- sirt@juniper.net
References
- http://www.securityfocus.com/bid/95403Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037593Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10773Vendor Advisory
- http://www.securityfocus.com/bid/95403Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037593Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10773Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.