Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-10605— Junos: SRX Series denial of service vulnerability in flowd due to crafted DHCP packet

Quick assessment

Affected
Juniper Networks Junos OS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Juniper vSRX和SRX都是美国瞻博网络(Juniper Networks)公司的产品。vSRX是一款防火墙模拟器。SRX是一款防火墙设备。Junos OS是其中的一套操作系统。DHCP是其中的一个动态主机配置协议。 带有DHCP或DHCP relay配置的Juniper vSRX和SRX Series设备上的Junos OS 12.1X46版本、12.3X48版本和15.1X49版本存在安全漏洞。远程攻击者可通过发送特制的数据包利用该漏洞造成拒绝服务(flowd进程崩溃)。

AI Predicted 7.5 Difficulty: Moderate EPSS 1.57% · P74
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-10605

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Junos: SRX Series denial of service vulnerability in flowd due to crafted DHCP packet
Source: CVE Program / CVE List V5
Vulnerability Description
On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended denial of service condition for the device(s). If the device is configured in high-availability, the RG1+ (data-plane) will fail-over to the secondary node. If the device is configured in stand-alone, there will be temporary traffic interruption until the flowd process is restored automatically. Sustained crafted packets may cause the secondary failover node to fail back, or fail completely, potentially halting flowd on both nodes of the cluster or causing flip-flop failovers to occur. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67 on vSRX or SRX Series; 12.3X48 prior to 12.3X48-D50 on vSRX or SRX Series; 15.1X49 prior to 15.1X49-D91, 15.1X49-D100 on vSRX or SRX Series.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Juniper vSRX和SRX Series设备Junos OS 输入验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Juniper vSRX和SRX都是美国瞻博网络(Juniper Networks)公司的产品。vSRX是一款防火墙模拟器。SRX是一款防火墙设备。Junos OS是其中的一套操作系统。DHCP是其中的一个动态主机配置协议。 带有DHCP或DHCP relay配置的Juniper vSRX和SRX Series设备上的Junos OS 12.1X46版本、12.3X48版本和15.1X49版本存在安全漏洞。远程攻击者可通过发送特制的数据包利用该漏洞造成拒绝服务(flowd进程崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67 -

II. Public POCs for CVE-2017-10605

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-10605

登录查看更多情报信息。

Vendor Advisories for CVE-2017-10605 (2)

Same Patch Batch · Juniper Networks · 2017-07-14 · 20 CVEs total

CVE-2017-2339 ScreenOS: XSS vulnerability in ScreenOS Firewall
CVE-2017-2349 SRX Series: Command injection vulnerability in SRX IDP feature.
CVE-2017-2348 Junos OS: jdhcpd daemon crash due to invalid IPv6 UDP packets
CVE-2017-2347 Junos: Denial of Service vulnerability in rpd daemon
CVE-2017-2346 MS-MPC or MS-MIC crash when passing large fragmented traffic through an ALG
CVE-2017-2345 Junos: snmpd denial of service upon receipt of crafted SNMP packet
CVE-2017-2344 Junos: Buffer overflow in sockets library
CVE-2017-2343 SRX Series: Hardcoded credentials in Integrated UserFW feature.
CVE-2017-2342 SRX Series: MACsec failure to report errors
CVE-2017-2341 Junos OS: VM to host privilege escalation in platforms with Junos OS running in a virtuali
CVE-2017-10601 Junos OS: Insufficient authentication for user login when a specific system configuration
CVE-2017-2338 ScreenOS: XSS vulnerability in ScreenOS Firewall
CVE-2017-2337 ScreenOS: XSS vulnerability in ScreenOS Firewall
CVE-2017-2336 ScreenOS: XSS vulnerability in ScreenOS Firewall
CVE-2017-2335 ScreenOS: XSS vulnerability in ScreenOS Firewall
CVE-2017-2314 Junos: RPD crash due to malformed BGP OPEN message
CVE-2017-10604 Junos OS: SRX Series: Cluster configuration sync failures occur if the root user account i
CVE-2017-10603 Junos OS: Local XML Injection through CLI command can lead to privilege escalation
CVE-2017-10602 Junos OS: buffer overflow vulnerability in Junos CLI

IV. Related Vulnerabilities

V. Comments for CVE-2017-10605

No comments yet


Leave a comment