CVE-2018-0049 is a NULL Pointer Dereference vulnerability in Juniper Networks Junos OS that allows an unauthenticated attacker to crash the Junos OS kernel by sending a specially crafted MPLS packet to an enabled interface. This can lead to a sustained Denial of Service (DoS) condition. The vulnerability affects numerous versions of Junos OS across various Juniper SRX, EX, QFX, and NFX series devices. Rated with a CVSS score of 7.5 (High), the vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. A successful exploit results in high impact to availability due to the sustained DoS. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. However, the vulnerability has received some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d76:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d77:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d66:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d70:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:r12-s10:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.