CVE-2019-0040 is an information leak and potential Denial of Service vulnerability affecting Juniper Networks Junos OS versions based on FreeBSD 10 or higher (typically 15.1+), specifically when the management interface (fxp0) is enabled. It allows external attackers to disclose internal network addressing and the existence of the management interface by crafting packets to port 111, which rpcbind should only be listening to internally. A high rate of these crafted packets can also lead to a partial Denial of Service. With a CVSS score of 9.1 (CRITICAL), this vulnerability has a network attack vector and low attack complexity, requiring no privileges or user interaction. The potential impact includes high confidentiality loss (information disclosure) and high availability loss (Denial of Service). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:-:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:a1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f2-s1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.