Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2018-0045 : What You Need to Know

Discover the impact of CVE-2018-0045, a vulnerability in Junos OS that can lead to RPD daemon crashes or remote code execution. Learn about affected systems, exploitation, and mitigation steps.

This CVE article provides details about a vulnerability in Junos OS that can lead to the crashing and restarting of the routing protocol daemon (RPD) process or potential remote code execution.

Understanding CVE-2018-0045

This vulnerability in Junos OS can be exploited by sending a specific control packet related to Draft-Rosen MVPN, causing the RPD process to crash and potentially leading to a denial of service.

What is CVE-2018-0045?

The vulnerability arises in Junos OS devices configured for Draft-Rosen multicast VPN with multicast-enabled VPNs using the PIM protocol. Attackers can crash the RPD process by continuously sending the same control packet.

The Impact of CVE-2018-0045

        Attack Vector: Adjacent Network
        Attack Complexity: Low
        Privileges Required: None
        Confidentiality Impact: High
        Integrity Impact: High
        Availability Impact: High

Technical Details of CVE-2018-0045

This section delves into the specifics of the vulnerability affecting various Junos OS versions and platforms.

Vulnerability Description

        The vulnerability allows attackers to crash the RPD process or potentially execute remote code by sending a specific control packet related to Draft-Rosen MVPN.

Affected Systems and Versions

        Junos OS versions prior to 12.1X46-D77, 12.3R12-S10, 12.3X48-D70, 15.1R4-S9, 15.1R6-S6, 15.1R7, 15.1F6, 15.1X49-D140, 15.1X53-D59, 15.1X53-D67, 15.1X53-D233, 15.1X53-D471, 15.1X53-D490, 16.1R4-S9, 16.1R5-S4, 16.1R6-S3, 16.1R7, 16.2R1-S6, 16.2R2-S6, 16.2R3, 17.1R1-S7, 17.1R2-S7, 17.1R3, 17.2R2-S4, 17.2R3, 17.3R2-S2, 17.3R3, 17.4R1-S3, 17.4R2, 18.1R2 are affected.

Exploitation Mechanism

        Attackers exploit the vulnerability by sending a specific control packet related to Draft-Rosen MVPN, crashing the RPD process.

Mitigation and Prevention

Learn how to mitigate and prevent the CVE-2018-0045 vulnerability.

Immediate Steps to Take

        Update Junos OS to the patched versions provided by Juniper Networks.

Long-Term Security Practices

        Regularly update Junos OS to the latest versions to prevent vulnerabilities.

Patching and Updates

        Apply the software releases provided by Juniper Networks to resolve the vulnerability.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now