| Summary | If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to delete the duplicate MAC address when the particular entry is not found in the internal MAC address table. This issue only occurs on MX Series devices with l2-backhaul VPN configured. No other products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S1 on MX Series; 16.1 versions prior to 16.1R4-S12, 16.1R6-S6 on MX Series; 16.2 versions prior to 16.2R2-S7 on MX Series; 17.1 versions prior to 17.1R2-S9 on MX Series; 17.2 versions prior to 17.2R1-S7, 17.2R2-S6 on MX Series; 17.3 versions prior to 17.3R2-S4, 17.3R3-S1 on MX Series; 17.4 versions prior to 17.4R1-S5 on MX Series; 18.1 versions prior to 18.1R2 on MX Series. |
|---|---|
| Publication Date | Oct. 11, 2018, 3:29 a.m. |
| Registration Date | March 1, 2021, 6:35 p.m. |
| Last Update | Nov. 21, 2024, 12:37 p.m. |
| CVSS3.0 : MEDIUM | |
| スコア | 5.3 |
|---|---|
| Vector | CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 攻撃元区分(AV) | 隣接 |
| 攻撃条件の複雑さ(AC) | 高 |
| 攻撃に必要な特権レベル(PR) | 不要 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 高 |
| CVSS2.0 : LOW | |
| Score | 2.9 |
|---|---|
| Vector | AV:A/AC:M/Au:N/C:N/I:N/A:P |
| 攻撃元区分(AV) | 隣接 |
| 攻撃条件の複雑さ(AC) | 中 |
| 攻撃前の認証要否(Au) | 不要 |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 低 |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:15.1:r3:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:r6:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:f4:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:r4:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:f6:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:f3:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:r2:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:r5:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:f5:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:15.1:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:16.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:16.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:16.1:r3:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:16.1:r2:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:16.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:16.2:r1:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:17.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:17.1:*:*:*:*:*:*:* | |||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:17.2:*:*:*:*:*:*:* | |||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:17.3:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:17.3:*:*:*:*:*:*:* | |||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:17.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:17.4:r1:*:*:*:*:*:* | |||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos:18.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos:18.1:*:*:*:*:*:*:* | |||||
| Title | Juniper Networks Junos OS における入力確認に関する脆弱性 |
|---|---|
| Summary | Juniper Networks Junos OS には、入力確認に関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Oct. 10, 2018, midnight |
| Registration Date | Feb. 27, 2019, 4:56 p.m. |
| Last Update | Feb. 27, 2019, 4:56 p.m. |
| ジュニパーネットワークス |
| Junos OS 15.1R7-S1 未満の 15.1 |
| Junos OS 16.1R4-S12 未満の16.1 |
| Junos OS 16.1R6-S6 未満の 16.1 |
| Junos OS 16.2R2-S7 未満の 16.2 |
| Junos OS 17.1R2-S9 未満の 17.1 |
| Junos OS 17.2R1-S7 未満の 17.2 |
| Junos OS 17.2R2-S6 未満の 17.2 |
| Junos OS 17.3R2-S4 未満の 17.3 |
| Junos OS 17.3R3-S1 未満の 17.3 |
| Junos OS 17.4R1-S5 未満の 17.4 |
| Junos OS 18.1R2 未満の 18.1 |
| Junos OS 15.1R7-S1 未満の 15.1 |
| Junos OS 16.1R4-S12 未満の16.1 |
| Junos OS 16.1R6-S6 未満の 16.1 |
| Junos OS 16.2R2-S7 未満の 16.2 |
| Junos OS 17.1R2-S9 未満の 17.1 |
| Junos OS 17.2R1-S7 未満の 17.2 |
| Junos OS 17.2R2-S6 未満の 17.2 |
| Junos OS 17.3R2-S4 未満の 17.3 |
| Junos OS 17.3R3-S1 未満の 17.3 |
| Junos OS 17.4R1-S5 未満の 17.4 |
| Junos OS 18.1R2 未満の 18.1 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2019年02月27日] 掲載 |
Feb. 27, 2019, 4:56 p.m. |