Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-0021— Junos OS: Short MacSec keys may allow man-in-the-middle attacks.

EPSS 0.16% · P36
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-0021

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Junos OS: Short MacSec keys may allow man-in-the-middle attacks.
Source: NVD (National Vulnerability Database)
Vulnerability Description
If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CAK) key are not configured, all remaining digits will be auto-configured to 0. Hence, Juniper devices configured with short MacSec keys are at risk to an increased likelihood that an attacker will discover the secret passphrases configured for these keys through dictionary-based and brute-force-based attacks using spoofed packets. Affected releases are Juniper Networks Junos OS: 14.1 versions prior to 14.1R10, 14.1R9; 14.1X53 versions prior to 14.1X53-D47; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D100; 15.1X53 versions prior to 15.1X53-D59; 16.1 versions prior to 16.1R3-S8, 16.1R4-S8, 16.1R5; 16.2 versions prior to 16.2R1-S6, 16.2R2; 17.1 versions prior to 17.1R2.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Juniper Networks Junos OS 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Juniper Networks Junos OS是美国瞻博网络(Juniper Networks)公司的一套专用于该公司的硬件设备的网络操作系统。该操作系统提供了安全编程接口和Junos SDK。 Juniper Networks Junos OS中存在信任管理问题漏洞,该漏洞源于网络系统或产品中缺乏有效的信任管理机制。攻击者可利用默认密码或者硬编码密码、硬编码证书等攻击受影响组件。以下版本受到影响:Juniper Junos OS 14.1版本,14.1X53版本,15.1版本,15.1X49版本,1
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Juniper NetworksJunos OS 14.1 ~ 14.1R10, 14.1R9 -

II. Public POCs for CVE-2018-0021

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0021

登录查看更多情报信息。

Same Patch Batch · Juniper Networks · 2018-04-11 · 8 CVEs total

CVE-2018-0016Junos OS: Kernel crash upon receipt of crafted CLNP datagrams
CVE-2018-0017SRX Series: Denial of service vulnerability in flowd daemon on devices configured with NAT
CVE-2018-0018SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass d
CVE-2018-0019Junos: Denial of service vulnerability in SNMP MIB-II subagent daemon (mib2d).
CVE-2018-0020Junos OS: rpd daemon cores due to malformed BGP UPDATE packet
CVE-2018-0022Junos OS: Mbuf leak due to processing MPLS packets in VPLS network.
CVE-2018-0023Junos Snapshot Administrator (JSNAPy) world writeable default configuration file permissio

IV. Related Vulnerabilities

V. Comments for CVE-2018-0021

No comments yet


Leave a comment