Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-0014— ScreenOS: Etherleak vulnerability found on ScreenOS device

EPSS 0.11% · P29
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-0014

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ScreenOS: Etherleak vulnerability found on ScreenOS device
Source: NVD (National Vulnerability Database)
Vulnerability Description
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Juniper ScreenOS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Juniper ScreenOS是美国瞻博网络(Juniper Networks)公司的一套运行于NetScreen系列防火墙中的操作系统。 Juniper ScreenOS 6.3.0r25版本中存在安全漏洞,该漏洞源于程序没有将Ethernet数据包填充为零。攻击者可利用该漏洞获取之前数据包中的系统内存或数据片段。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Juniper NetworksScreenOS all ~ 6.3.0r25 -

II. Public POCs for CVE-2018-0014

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0014

Please Login to view more intelligence information

Same Patch Batch · Juniper Networks · 2018-01-10 · 12 CVEs total

CVE-2018-0001Junos: Unauthenticated Remote Code Execution through J-Web interface
CVE-2018-0002MX series, SRX series: Junos OS: Denial of service vulnerability in Flowd on devices with
CVE-2018-0003Junos OS: A crafted MPLS packet may lead to a kernel crash
CVE-2018-0004Junos OS: Kernel Denial of Service Vulnerability
CVE-2018-0005Security Bulletin: Junos OS: MAC move limit configured to drop traffic may forward traffic
CVE-2018-0006Junos OS: bbe-smgd process denial of service while processing VLAN authentication requests
CVE-2018-0008Junos OS: commit script may allow unauthenticated root login upon reboot
CVE-2018-0009SRX Series: Firewall bypass vulnerability when UUID with leading zeros is configured.
CVE-2018-0011Junos Space: Reflected XSS vulnerability in Junos Space management interface
CVE-2018-0012Junos Space: Local privilege escalation vulnerability in Junos Space
CVE-2018-0013Junos Space: Local File Inclusion Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2018-0014

No comments yet


Leave a comment