CVE-2017-2345 is a critical vulnerability affecting Juniper Networks Junos OS devices with SNMP enabled. A remote, unauthenticated attacker can send a crafted SNMP packet to cause the snmpd daemon to crash, leading to a partial denial of service. This vulnerability also presents a potential for remote code execution. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. It affects numerous Junos OS versions across multiple release trains. While there is no evidence of active exploitation (KEV: No) and no public exploit code available (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:*:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.