CVE-2019-0049 describes a Denial of Service vulnerability in Juniper Junos OS devices. A specific sequence of BGP session restarts on a remote peer can cause the local routing protocol daemon (RPD) to crash and restart, leading to prolonged service disruption. This vulnerability affects various Junos OS versions, particularly when BGP graceful restart helper mode is enabled, which is the default configuration. The vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, requiring no user interaction, and resulting in high availability impact. While the EPSS score is low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score is moderate at 51/100. Currently, there is no known active exploitation of this vulnerability, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Furthermore, there is minimal community discussion or media coverage surrounding this CVE, suggesting it has not garnered significant attention from threat actors or the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:-:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r1:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r2:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r3:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r3-s10:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.