CVE-2019-0066 is a denial-of-service vulnerability in Juniper Networks Junos OS, specifically affecting the Next-Generation Multicast VPN (NG-mVPN) service. An attacker can trigger this by sending a specially crafted IPv4 packet to a device running BGP, causing the routing protocol daemon (rpd) process to crash. This issue impacts various Junos OS versions across different product lines, including SRX Series. The vulnerability has a CVSS v3.1 score of 7.5 (High), indicating a significant risk. It is a network-based attack with low attack complexity, requiring no user interaction or privileges, and its primary impact is a sustained denial of service. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.1X49, < 15.1X49-D150CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 16.2, < 16.2R2-S7CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:a1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.