CVE-2018-0016
Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'clns-routing' or ES-IS is explicitly configured. Devices with without CLNS enabled are not vulnerable to this issue. Devices with IS-IS configured on the interface are not vulnerable to this issue unless CLNS routing is also enabled. This issue only affects devices running Junos OS 15.1.
Read full descriptionShow less
Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5; 15.1X49 versions prior to 15.1X49-D60; 15.1X53 versions prior to 15.1X53-D66, 15.1X53-D233, 15.1X53-D471. Earlier releases are unaffected by this vulnerability, and the issue has been resolved in Junos OS 16.1R1 and all subsequent releases.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.07%
- Percentile among all scored CVEs: 90
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2018-0016",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "sirt@juniper.net",
"affectedData": [
{
"vendor": "Juniper Networks",
"product": "Junos OS",
"versions": [
{
"status": "affected",
"version": "15.1",
"lessThan": "15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5",
"versionType": "custom"
},
{
"status": "affected",
"version": "15.1X49",
"lessThan": "15.1X49-D60",
"versionType": "custom"
},
{
"status": "affected",
"version": "15.1X53",
"lessThan": "15.1X53-D66, 15.1X53-D233, 15.1X53-D471",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-04-11T19:29:00.277",
"references": [
{
"url": "http://www.securityfocus.com/bid/103747",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "sirt@juniper.net"
},
{
"url": "http://www.securitytracker.com/id/1040784",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "sirt@juniper.net"
},
{
"url": "https://kb.juniper.net/JSA10844",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "sirt@juniper.net"
},
{
"url": "http://www.securityfocus.com/bid/103747",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1040784",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kb.juniper.net/JSA10844",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'clns-routing' or ES-IS is explicitly configured. Devices with without CLNS enabled are not vulnerable to this issue. Devices with IS-IS configured on the interface are not vulnerable to this issue unless CLNS routing is also enabled. This issue only affects devices running Junos OS 15.1. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5; 15.1X49 versions prior to 15.1X49-D60; 15.1X53 versions prior to 15.1X53-D66, 15.1X53-D233, 15.1X53-D471. Earlier releases are unaffected by this vulnerability, and the issue has been resolved in Junos OS 16.1R1 and all subsequent releases."
},
{
"lang": "es",
"value": "La recepción de un datagrama CLNP (Connectionless Network Protocol) destinado a la interfaz de un dispositivo Junos OS puede resultar en un cierre inesperado del kernel o conducir a la ejecución remota de código. Los dispositivos solo son vulnerables al datagrama CLNP especialmente manipulado si 'clns-routing' o ES-IS están explícitamente configurados. Los dispositivos sin CLNS habilitado no son vulnerables a este problema. Los dispositivos con IS-IS configurado en la interfaz no son vulnerables, a no ser que el enrutamiento CLNS esté también habilitado. Este problema solo afecta a dispositivos que ejecutan Junos OS 15.1. Las versiones afectadas son Juniper Networks Junos OS: 15.1 en versiones anteriores a la 15.1F5-S3, 15.1F6-S8, 15.1F7, 15.1R5; 15.1X49 en versiones anteriores a la15.1X49-D60; 15.1X53 en versiones anteriores a la 15.1X53-D66, 15.1X53-D233 y 15.1X53-D471. Los lanzamientos anteriores no se han visto afectados por esta vulnerabilidad; el problema se ha resuelto en Junos OS 16.1R1 y en todas las versiones posteriores."
}
],
"lastModified": "2026-06-17T01:29:23.647",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:15.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD0952C4-FFCC-4A78-ADFC-289BD6E269DB"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0D3EA8F-4D30-4383-AF2F-0FB6D822D0F3"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E6CD065-EC06-4846-BD2A-D3CA7866070F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7620D01-1A6B-490F-857E-0D803E0AEE56"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1:r4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A1545CE-279F-4EE2-8913-8F3B2FAFE7F6"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99A79967-FBAD-4205-AF27-A64C2AA34E86"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F340A343-BEAB-42E9-A627-5BCD4B82427E"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "027BAB70-7DB8-4642-8B6B-F7C3DF9149DE"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DA6701B-90D2-4286-8414-96E45B37364A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4409D08-E682-4D5C-8A23-3F173F88BEF9"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f5:s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "795DE6D9-86ED-46DE-8496-024494B74C79"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f6:s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD8A323E-64CE-46BE-AFF6-5F11ACB5A40B"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1f6:s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83773828-2475-4A65-ACDE-B6AD2588AB8B"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20DABA6A-FA7A-4289-8C6A-2B93689A5440"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D90D8985-34EF-44CC-A9A7-CB0FD22676F2"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18468579-0195-4DDE-BAA5-4BE4068F3A69"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E5FAA97-171F-4DB9-B78E-6E1A5F34336A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "870244F3-1C05-4F10-A205-5189BB860F46"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d40:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "235EE40B-AA15-4F39-8087-A051F4F70995"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d45:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17330544-3AFC-463E-A146-2840A8AE17D2"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d50:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8ABA301F-7866-42A5-8391-E07BEAFF06FA"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x49:d55:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "884E4A85-ED42-4391-9FDD-9052F957743A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B71FB14A-67D4-4EDD-BB32-07764F5AFA6E"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E87C765-8D68-404A-AC71-3F22A7260E8C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E3B807C-196D-42B8-9042-7582A1366772"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83FEEE8F-9279-46F2-BAF9-A60537020C61"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d30:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F294E43-73FA-4EF3-90F2-EE29C56D6573"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d32:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDDE1048-BFEA-4A3E-8270-27C538A68837"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d33:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC517CD0-FF35-498F-AD33-683B43CA3829"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d34:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53F7E1C5-BFA9-426C-9F95-3EA5DB458C7E"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d50:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D58997E6-96B4-4930-A29D-B49D06DFA9D5"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d51:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFB887FD-D3FB-439F-9A89-CC367A74DB00"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d52:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDA46912-D173-49C5-A0A1-64BD0889D3A0"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d55:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BEE4EE4-18D9-4FA9-9A02-917240B851AA"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d57:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "188FED65-8A81-4BB0-B10B-8CA17B4F71CC"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d58:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F03E847-748B-43BD-B6C1-BFDECE99BC3C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d60:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "962CCED8-E321-4878-9BE6-0DC33778559A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d61:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B08B97A-5D4D-405B-A1C4-9E327E4EED35"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d62:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "738C1061-E8B8-4924-AFE9-5E59F22CA4A8"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d63:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9071DC8C-D0AA-448E-82BF-7C801199193F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d64:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "395CC50B-9042-4B12-9A1C-A8D5D571DC25"
},
{
"criteria": "cpe:2.3:o:juniper:junos:15.1x53:d65:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0396190-54A5-4F11-8530-B5EC7BCBC85A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:juniper:junos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1EA2466C-D443-4A63-AA4F-1AE4EE5DA02A"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "sirt@juniper.net"
}