CVE-2018-0063 is a denial-of-service vulnerability affecting Junos OS 17.3R3, specifically impacting the management interface of Juniper devices. An attacker can flood the management interface with ARP requests, exhausting the private Internal Routing Interfaces (IRIs) next-hop limit and preventing new next-hops from being learned. This leads to a sustained denial of service, indicated by the error "%KERN-4: Nexthop index allocation failed: private index space exhausted." The vulnerability has a CVSS v3.1 score of 6.5 (Medium), indicating an adjacent network attack vector (AV:A) with low attack complexity (AC:L) and high impact on availability (A:H). There is no impact on confidentiality or integrity. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there any evidence of active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.3:*:*:*:*:*:*:* | ||
>= 17.3R3, < 17.3R3-S1CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.