ID

VAR-201705-3364


CVE

CVE-2017-2300


TITLE

Juniper Networks SRX Runs on a series service gateway chassis cluster Junos OS Data processing vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-004598

DESCRIPTION

On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets. Juniper Junos is prone to a denial-of-service vulnerability. Attackers can exploit this issue to crash and restart the affected device, denying service to legitimate users. Junos OS is a network operating system dedicated to the company's hardware systems. An attacker could exploit this vulnerability by means of a specially crafted multicast packet to cause a denial of service (the flowd daemon crashes). The following releases are affected: Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60

Trust: 1.98

sources: NVD: CVE-2017-2300 // JVNDB: JVNDB-2017-004598 // BID: 95400 // VULHUB: VHN-110503

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:lteversion:12.1x46

Trust: 1.0

vendor:junipermodel:junosscope:lteversion:12.3x48

Trust: 1.0

vendor:junipermodel:junos osscope: - version: -

Trust: 0.8

vendor:junipermodel:junosscope:eqversion:12.1x46

Trust: 0.6

vendor:junipermodel:junosscope:eqversion:12.3x48

Trust: 0.6

vendor:junipermodel:junos 15.1x49-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x49-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x49-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x49-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x49-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d60scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d55scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d51scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d50scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d46scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d45scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d37scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d36scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d26scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 15.1x49-d60scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d40scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d65scope:neversion: -

Trust: 0.3

sources: BID: 95400 // JVNDB: JVNDB-2017-004598 // CNNVD: CNNVD-201701-319 // NVD: CVE-2017-2300

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-2300
value: HIGH

Trust: 1.0

NVD: CVE-2017-2300
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201701-319
value: HIGH

Trust: 0.6

VULHUB: VHN-110503
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-2300
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-110503
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-2300
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-110503 // JVNDB: JVNDB-2017-004598 // CNNVD: CNNVD-201701-319 // NVD: CVE-2017-2300

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-19

Trust: 0.9

sources: VULHUB: VHN-110503 // JVNDB: JVNDB-2017-004598 // NVD: CVE-2017-2300

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201701-319

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201701-319

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004598

PATCH

title:JSA10768url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10768&actp=METADATA

Trust: 0.8

title:Juniper Junos Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=66981

Trust: 0.6

sources: JVNDB: JVNDB-2017-004598 // CNNVD: CNNVD-201701-319

EXTERNAL IDS

db:NVDid:CVE-2017-2300

Trust: 2.8

db:BIDid:95400

Trust: 2.0

db:JUNIPERid:JSA10768

Trust: 2.0

db:SECTRACKid:1037597

Trust: 1.7

db:JVNDBid:JVNDB-2017-004598

Trust: 0.8

db:CNNVDid:CNNVD-201701-319

Trust: 0.7

db:VULHUBid:VHN-110503

Trust: 0.1

sources: VULHUB: VHN-110503 // BID: 95400 // JVNDB: JVNDB-2017-004598 // CNNVD: CNNVD-201701-319 // NVD: CVE-2017-2300

REFERENCES

url:http://www.securityfocus.com/bid/95400

Trust: 1.7

url:https://kb.juniper.net/jsa10768

Trust: 1.7

url:http://www.securitytracker.com/id/1037597

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-2300

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2300

Trust: 0.8

url:http://www.juniper.net/

Trust: 0.3

url:http://www.juniper.net/us/en/products-services/nos/junos/

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10768&actp=search

Trust: 0.3

sources: VULHUB: VHN-110503 // BID: 95400 // JVNDB: JVNDB-2017-004598 // CNNVD: CNNVD-201701-319 // NVD: CVE-2017-2300

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 95400

SOURCES

db:VULHUBid:VHN-110503
db:BIDid:95400
db:JVNDBid:JVNDB-2017-004598
db:CNNVDid:CNNVD-201701-319
db:NVDid:CVE-2017-2300

LAST UPDATE DATE

2025-04-20T23:37:56.002000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-110503date:2019-10-03T00:00:00
db:BIDid:95400date:2017-01-23T06:05:00
db:JVNDBid:JVNDB-2017-004598date:2017-06-30T00:00:00
db:CNNVDid:CNNVD-201701-319date:2019-10-23T00:00:00
db:NVDid:CVE-2017-2300date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-110503date:2017-05-30T00:00:00
db:BIDid:95400date:2017-01-11T00:00:00
db:JVNDBid:JVNDB-2017-004598date:2017-06-30T00:00:00
db:CNNVDid:CNNVD-201701-319date:2017-01-13T00:00:00
db:NVDid:CVE-2017-2300date:2017-05-30T14:29:00.597