Junos OS: Denial of service vulnerability in telnetd
Published Oct 13, 2017
5.3
MEDIUMCVSS 3.0
EPSS 1.80%
Description
A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9; 14.1X53 prior to 14.1X53-D50; 14.2 prior to 14.2R7-S9, 14.2R8; 15.1 prior to 15.1F2-S16, 15.1F5-S7, 15.1F6-S6, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D90; 15.1X53 prior to 15.1X53-D47; 16.1 prior to 16.1R4-S1, 16.1R5; 16.2 prior to 16.2R1-S3, 16.2R2;
Affected products
-
Affected
- 12.1X46 prior to 12.1X46-D71
- 12.3X48 prior to 12.3X48-D50
- 14.1 prior to 14.1R8-S5, 14.1R9
- 14.1X53 prior to 14.1X53-D50
- 14.2 prior to 14.2R7-S9, 14.2R8
- 15.1 prior to 15.1F2-S16, 15.1F5-S7, 15.1F6-S6, 15.1R5-S2, 15.1R6
- 15.1X49 prior to 15.1X49-D90
- 15.1X53 prior to 15.1X53-D47
- 16.1 prior to 16.1R4-S1, 16.1R5
- 16.2 prior to 16.2R1-S3, 16.2R2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Juniper Networks | Junos OS | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Disabling the telnet service would completely mitigate this issue.
Reducing the maximum number of connections to a value between 1 and 250 would help mitigate this vulnerability. For example: user@junos# set system services telnet connection-limit 100
It is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device from trusted, administrative networks or hosts.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-2268 Advisory
- https://kb.juniper.net/JSA10817 x_refsource_CONFIRMMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-2268 | Advisory | |
| https://kb.juniper.net/JSA10817 | x_refsource_CONFIRMMitigationVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data