CVE-2017-2348 - CVE House
Back to Database
Status published High CVE-2017-2348

Junos OS: jdhcpd daemon crash due to invalid IPv6 UDP packets

Vulnerability Description

The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon receipt of an invalid IPv6 UDP packet. Both high CPU utilization and repeated crashes of the jdhcpd daemon can result in a denial of service as DHCP service is interrupted. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 14.1X53 prior to 14.1X53-D12, 14.1X53-D38, 14.1X53-D40 on QFX, EX, QFabric System; 15.1 prior to 15.1F2-S18, 15.1R4 on all products and platforms; 15.1X49 prior to 15.1X49-D80 on SRX; 15.1X53 prior to 15.1X53-D51, 15.1X53-D60 on NFX, QFX, EX.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2348

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Juniper Networks

View all reports →

Affected Software

Junos OS
Vulnerable Versions:
14.1X53 prior to 14.1X53-D12, 14.1X53-D38, 14.1X53-D40, 15.1 prior to 15.1F2-S18, 15.1R4, 15.1X49 prior to 15.1X49-D80, 15.1X53 prior to 15.1X53-D51, 15.1X53-D60

Timeline

Official Publish: July 14th, 2017
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.