CVE-2019-0037 Details
Description
In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solicit messages received from a DHCPv6 client. By continuously sending the same crafted packet, an attacker can repeatedly crash the jdhcpd process causing a sustained Denial of Service (DoS) to both IPv4 and IPv6 clients. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D171, 15.1X49-D180; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D496; 16.1 versions prior to 16.1R3-S10, 16.1R7-S4; 16.2 versions prior to 16.2R2-S8; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S2; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R1-S2. This issue does not affect Junos OS releases prior to 15.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA10926 | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/107894 | CVE | Broken Link |
| https://kb.juniper.net/JSA10926 | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/107894 | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 15.1 r1 15.1 r2 15.1 r3 15.1 r4 15.1 r5 15.1 r6 15.1 r7 15.1x49-d30 15.1x49-d60 15.1x49-d140 15.1x49-d150 15.1x49-d160 15.1x53-d50 15.1x53-d51 15.1x53-d52 15.1x53-d55 15.1x53-d57 15.1x53-d58 15.1x53-d59 16 r2 16 r3 16 r4 16 r5 16 r6 16 r7 16.2 r1 16.2 r2 16.2 r2-s7 17.1 r1 17.1 r2 17.1 r2-s9 17.2 r1 17.2 r2 17.2 r3 17.2 r1-s7 17.3 r1 17.3 r2 17.3 r3 17.3 r3-s2 17.4 r1 17.4 r1-s5 17.4 r2 18.1 r1 18.1 r2 18.1 r3 18.1 r3-s1 18.2 r1 18.2x75-d10 18.3 r1 18.3 r1-s1 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 18, 2022 | Modified Analysis | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Apr 16, 2019 | Initial Analysis | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 10, 2019 | CVE Modified | [email protected] |