Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106505
Category:JunOS Local Security Checks
Title:Juniper Networks Junos OS SRX Series: DoS Vulnerability in flowd
Summary:Junos OS on SRX series is prone to a denial of service vulnerability.
Description:Summary:
Junos OS on SRX series is prone to a denial of service vulnerability.

Vulnerability Insight:
The flowd daemon on the primary node of an SRX Series chassis cluster may
crash and restart when attempting to synchronize a multicast session created via crafted multicast packets. Upon
the flowd crash, data plane redundancy groups will fail over to the secondary node in the chassis cluster while
flowd on the primary node restarts.

This issue only occurs in chassis cluster configurations, and only if PIM is enabled on the services gateway.

Vulnerability Impact:
An attacker may cause a denial of service condition.

Affected Software/OS:
Junos OS 12.1X46, 12.3X48 and 15.1X49 on SRX Series.

Solution:
New builds of Junos OS software are available from Juniper. As a workaround
disable transit multicast traffic by disabling PIM and isolate or disable the secondary node of the chassis
cluster until the fix is implemented.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-2300
BugTraq ID: 95400
http://www.securityfocus.com/bid/95400
http://www.securitytracker.com/id/1037597
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.