CVE-2019-0002 describes a critical vulnerability affecting Juniper EX2300 and EX3400 series switches running specific versions of Junos OS. A misconfiguration in stateless firewall filters using the 'policer' action can prevent them from taking effect, potentially allowing unauthorized network traffic. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1x53CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x53:d50:*:*:*:*:*:* | ||
15.1x53CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x53:d51:*:*:*:*:*:* | ||
15.1x53CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x53:d52:*:*:*:*:*:* | ||
15.1x53CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x53:d55:*:*:*:*:*:* | ||
15.1x53CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x53:d57:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.