CVE-2019-0075 is a denial-of-service vulnerability affecting Juniper Networks Junos OS on SRX Series devices when processing specific Protocol Independent Multicast (PIM) messages. An unauthenticated attacker can remotely trigger a crash of the srxpfe process, leading to an FPC reboot and sustained denial of service. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, resulting in high availability impact. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.3X48, < 12.3X48-D80CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 15.1X49, < 15.1X49-D160CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 17.3, < 17.3R3-S7CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.1, < 18.1R3-S8CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.2, < 18.2R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.