Vulnerability Name:

CVE-2007-6372 (CCN-39042)

Assigned:2007-12-04
Published:2007-12-04
Updated:2011-04-29
Summary:Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that trigger session flapping.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-6372

Source: MITRE
Type: CNA
CVE-2008-2169

Source: MITRE
Type: CNA
CVE-2008-2170

Source: MITRE
Type: CNA
CVE-2008-2171

Source: MITRE
Type: CNA
CVE-2008-2172

Source: MITRE
Type: CNA
CVE-2008-2173

Source: CCN
Type: SA28100
Juniper JUNOS BGP UPDATE Message Processing Denial of Service

Source: SECUNIA
Type: Vendor Advisory
28100

Source: CCN
Type: SA30028
Hitachi GR Series BGP UPDATE Message Processing Denial of Service

Source: CCN
Type: SA30054
ALAXALA Networks AX Series BGP UPDATE Message Processing Denial of Service

Source: CCN
Type: SECTRACK ID: 1019100
Juniper JUNOS BGP and IPv6 Bugs Let Remote Users Deny Service

Source: CCN
Type: Juniper Networks Web site
Juniper Networks JUNOS

Source: CCN
Type: US-CERT VU#929656
BGP implementations do not properly handle UPDATE messages

Source: CERT-VN
Type: US Government Resource
VU#929656

Source: OSVDB
Type: UNKNOWN
39157

Source: CCN
Type: OSVDB ID: 39157
Juniper Junos Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 39158
Juniper Junos IPv6 Traffic Handling Unspecified Remote Overflow DoS

Source: CCN
Type: OSVDB ID: 44942
Hitachi GR Series Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 44947
ALAXALA Networks AX Series Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 45430
Avici Routers Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 45431
Century Routers Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 45432
AlaxalA AX Routers Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 45433
Hitachi GR Routers Malformed BGP Update Message Remote DoS

Source: CCN
Type: OSVDB ID: 45434
Yamaha Routers Malformed BGP Update Message Remote DoS

Source: BID
Type: UNKNOWN
26869

Source: CCN
Type: BID-26869
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability

Source: BID
Type: UNKNOWN
28999

Source: CCN
Type: BID-28999
Multiple Vendors Malformed BGP 'UPDATE' Message Remote Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1019100

Source: VUPEN
Type: Vendor Advisory
ADV-2007-4223

Source: XF
Type: UNKNOWN
multiple-bgp-update-dos(39042)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:juniper:junos:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.4:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.5:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.6:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.3:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:juniper:junos:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.4:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.4:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.5:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:7.6:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:junos:8.0:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:gr4000:*:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:gr3000:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    juniper junos 7.3
    juniper junos 7.4
    juniper junos 7.5
    juniper junos 7.6
    juniper junos 8.0
    juniper junos 8.1
    juniper junos 8.2
    juniper junos 8.3
    juniper junos 8.4
    juniper junos 7.3
    juniper junos 8.4
    juniper junos 7.4
    juniper junos 7.5
    juniper junos 7.6
    juniper junos 8.0
    hitachi gr4000 *
    hitachi gr3000 *