383
VMScore

CVE-2017-10611

Published: 13/10/2017 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE processing can result in an extended denial of service condition. This issue only affects the following platforms: (1) EX2200, EX3300, XRE200 (2) MX Series routers with MPC7E/8E/9E PFEs installed, and only if 'extended-statistics' are enabled under the [edit chassis] configuration. Affected releases are Juniper Networks Junos OS 14.1 before 14.1R8-S5, 14.1R9 on MX Series; 14.1X53 before 14.1X53-D46, 14.1X53-D50 on EX2200, EX3300, XRE200; 14.2 before 14.2R7-S9, 14.2R8 on MX Series; 15.1 before 15.1F5-S8, 15.1F6-S8, 15.1R5-S3, 15.1R6 on MX Series; 16.1 before 16.1R4-S5, 16.1R5, 16.1R6 on MX Series; 16.1X65 before 16.1X65-D45 on EX2200, EX3300, XRE200; 16.2 before 16.2R2-S1, 16.2R3 on MX Series; 17.1 before 17.1R2-S2, 17.1R3 on MX Series; 17.2 before 17.2R1-S3, 17.2R2 on MX Series; 17.2X75 before 17.2X75-D50 on MX Series; 17.3 before 17.3R1-S1, 17.3R2 on MX Series. No other Juniper Networks products or platforms are affected by this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 14.1

juniper junos 14.1x53

juniper junos 14.2

juniper junos 15.1

juniper junos 16.1

juniper junos 16.1x65

juniper junos 16.2

juniper junos 17.1

juniper junos 17.2

juniper junos 17.2x75

juniper junos 17.3