CVE-2017-2312 is a denial-of-service vulnerability affecting Juniper Networks devices running specific versions of Junos OS with LDP enabled. A specially crafted LDP packet can cause the routing protocol daemon (rpd) to consume memory, eventually leading to a crash and restart of the process. This issue impacts Junos OS versions prior to 16.2R1. Rated with a CVSS v3.0 score of 6.5 (Medium), the vulnerability has a network attack vector and low attack complexity, allowing an authenticated attacker to cause a high impact on availability. There is no impact on confidentiality or integrity. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, indicating limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:*:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r1:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r2:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r3:*:*:*:*:*:* | ||
13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:13.3:r4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.