CVE-2018-0014

UnknownEPSS 0.60%

Last modified

CVE-2018-0014 is a vulnerability of currently unknown severity. Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. EPSS estimates a 0.60% chance of exploitation in the next 30 days.

Description

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.

Metrics

EPSS Probability
0.60%

44.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JuniperScreenos6.3.0r1
JuniperScreenos6.3.0r2
JuniperScreenos6.3.0r3
JuniperScreenos6.3.0r4
JuniperScreenos6.3.0r5
JuniperScreenos6.3.0r6
JuniperScreenos6.3.0r7
JuniperScreenos6.3.0r8
JuniperScreenos6.3.0r9
JuniperScreenos6.3.0r10
JuniperScreenos6.3.0r11
JuniperScreenos6.3.0r12
JuniperScreenos6.3.0r13
JuniperScreenos6.3.0r14
JuniperScreenos6.3.0r15
JuniperScreenos6.3.0r16
JuniperScreenos6.3.0r17
JuniperScreenos6.3.0r18
JuniperScreenos6.3.0r19
JuniperScreenos6.3.0r20
JuniperScreenos6.3.0r21
JuniperScreenos6.3.0r22
JuniperScreenos6.3.0r23
JuniperScreenos6.3.0r24
JuniperScreenos6.3.0r25

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-0014?
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
How severe is CVE-2018-0014?
Severity scoring for CVE-2018-0014 is pending analysis. The EPSS model estimates a 0.60% probability of exploitation in the next 30 days.
How do I fix CVE-2018-0014?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-0014?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST