CVE detail

CVE-2019-0056 — CVE-2019-0056

Published 2019-10-09 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.5
CVSS v3
0–10 scale
0.0132
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

This issue only affects devices with three (3) or more MPC10's installed in a single chassis with OSPF enabled and configured on the device. An Insufficient Resource Pool weakness allows an attacker to cause the device's Open Shortest Path First (OSPF) states to transition to Down, resulting in a Denial of Service (DoS) attack. This attack requires a relatively large number of specific Internet Mixed (IMIXed) types of genuine and valid IPv6 packets to be transferred by the attacker in a relatively short period of time, across three or more PFE's on the device at the same time. Continued receipt of the traffic sent by the attacker will continue to cause OSPF to remain in the Down starting state, or flap between other states and then again to Down, causing a persistent Denial of Service. Thi

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 18.1R2-S4, 18.1R3-S5, 18.2R1-S5, 18.2R2-S3, 18.2R3, 18.2X75-D50, 18.3R1-S4, 18.3R2, 18.3R3, 18.4R1-S2, 18.4R2, 19.1R1, and all subsequent releases.

workarounds

There are no known workarounds for this issue.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=18.1<18.1R2-S4, 18.1R3-S518.1R2-S4, 18.1R3-S5advisory ↗
Juniper Networks Junos OS>=18.1X75-D10<18.1X75*18.1X75*advisory ↗
Juniper Networks Junos OS>=18.2<18.2R1-S5, 18.2R2-S3, 18.2R318.2R1-S5, 18.2R2-S3, 18.2R3advisory ↗
Juniper Networks Junos OS>=18.2X75<18.2X75-D5018.2X75-D50advisory ↗
Juniper Networks Junos OS>=18.3<18.3R1-S4, 18.3R2, 18.3R318.3R1-S4, 18.3R2, 18.3R3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S2, 18.4R218.4R1-S2, 18.4R2advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.