Lucene search

K
cveJuniperCVE-2017-2330
HistoryApr 24, 2017 - 3:59 p.m.

CVE-2017-2330

2017-04-2415:59:00
CWE-834
juniper
web.nvd.nist.gov
36
cve-2017-2330
denial of service
vulnerability
juniper networks
northstar controller
unauthenticated
local user
fork bomb
rabbit virus

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

21.1%

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are consumed on the system, leading to a denial of service to the entire system until it is restarted. Continued attacks by an unauthenticated, local user, can lead to persistent denials of services.

Affected configurations

Nvd
Node
junipernorthstar_controllerRange2.1.0
VendorProductVersionCPE
junipernorthstar_controller*cpe:2.3:a:juniper:northstar_controller:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "NorthStar Controller Application",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "status": "affected",
        "version": "prior to version 2.1.0 Service Pack 1"
      }
    ]
  }
]

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

21.1%

Related for CVE-2017-2330