VulnerabilityModified
CVE-2018-0005
This can lead to denials of services or other unintended conditions.
HIGH 8.8EPSS 0.72%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or other unintended conditions. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D40; 15.1X53 versions prior to 15.1X53-D55; 15.1 versions prior to 15.1R7.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- juniper/junos
- Source
- sirt@juniper.net
References
- http://www.securitytracker.com/id/1040182Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10833Mitigation, Vendor Advisory
- http://www.securitytracker.com/id/1040182Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10833Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.