Junos OS: Stateless IP firewall filter rules stop working as expected after reboot or upgrade
Published Jul 11, 2018
7.5
HIGHCVSS 3.0
EPSS 1.76%
Description
After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can be verified by running the command: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Note: when the issue occurs, it does not show the applied firewall filter. The correct output should show the applied firewall filter, for example: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Input Filters: FIREWAL_FILTER_NAME-<interface_name> This issue affects firewall filters for every address family. Affected releases are Juniper Networks Junos OS: 15.1R4, 15.1R5, 15.1R6 and SRs based on these MRs. 15.1X8 versions prior to 15.1X8.3.
Affected products
-
- Version 15.1R4, 15.1R5, 15.1R6StatusaffectedConstraints-
- Version 15.1X8StatusaffectedConstraints<15.1X8.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: 15.1R7, 15.1X8.3 and all subsequent releases.
No CWE recorded.
References (4)
- http://www.securityfocus.com/bid/104720 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041315 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0850 Advisory
- https://kb.juniper.net/JSA10859 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/104720 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1041315 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0850 | Advisory | |
| https://kb.juniper.net/JSA10859 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.