CVE-2018-0032
The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can result in an extended denial of service condition for the device. This issue only affects the specific versions of Junos OS listed within this advisory. Earlier releases are unaffected by this vulnerability. This crafted BGP UPDATE does not propagate to other BGP peers. Affected releases are Juniper Networks Junos OS: 16.1X65 versions prior to 16.1X65-D47; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D110; 17.3 versions prior to 17.3R1-S4, 17.3R2; 17.4 versions prior to 17.4R1-S3, 17.4R2.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.69%
- Percentile among all scored CVEs: 76
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2018-0032",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "sirt@juniper.net",
"affectedData": [
{
"vendor": "Juniper Networks",
"product": "Junos OS",
"versions": [
{
"status": "affected",
"version": "16.1X65",
"lessThan": "16.1X65-D47",
"versionType": "custom"
},
{
"status": "affected",
"version": "17.2X75",
"lessThan": "17.2X75-D91, 17.2X75-D110",
"versionType": "custom"
},
{
"status": "affected",
"version": "17.3",
"lessThan": "17.3R1-S4, 17.3R2",
"versionType": "custom"
},
{
"status": "affected",
"version": "17.4",
"lessThan": "17.4R1-S3, 17.4R2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-07-11T18:29:00.573",
"references": [
{
"url": "http://www.securitytracker.com/id/1041337",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "sirt@juniper.net"
},
{
"url": "https://kb.juniper.net/JSA10866",
"tags": [
"Vendor Advisory"
],
"source": "sirt@juniper.net"
},
{
"url": "http://www.securitytracker.com/id/1041337",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kb.juniper.net/JSA10866",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can result in an extended denial of service condition for the device. This issue only affects the specific versions of Junos OS listed within this advisory. Earlier releases are unaffected by this vulnerability. This crafted BGP UPDATE does not propagate to other BGP peers. Affected releases are Juniper Networks Junos OS: 16.1X65 versions prior to 16.1X65-D47; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D110; 17.3 versions prior to 17.3R1-S4, 17.3R2; 17.4 versions prior to 17.4R1-S3, 17.4R2."
},
{
"lang": "es",
"value": "La recepción de un BGP UPDATE manipulado puede conducir al cierre inesperado y reinicio de un demonio de proceso de enrutamiento (RPD). La recepción repetida del mismo BGP UPDATE manipulado puede resultar en una condición de denegación de servicio (DoS) extendida para los dispositivos. Este problema solo afecta a las versiones específicas de Junos OS listadas en este advisory. Las versiones anteriores no se han visto afectadas por esta vulnerabilidad. Este BGP UPDATE manipulado no se propaga a otros peers BGP. Las versiones afectadas son Juniper Networks Junos OS: 16.1X65 en versiones anteriores a 16.1X65-D47; 17.2X75 en versiones anteriores a 17.2X75-D91, 17.2X75-D110; 17.3 en versiones anteriores a 17.3R1-S4, 17.3R2; 17.4 en versiones anteriores a 17.4R1-S3 y 17.4R2."
}
],
"lastModified": "2026-06-17T01:29:26.480",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA096D02-3E65-4D84-AB38-DE6DC7270097"
},
{
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d30:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A347C15-3ABC-4B11-A9BB-5DF1C73538EE"
},
{
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d35:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBCD72E3-22CE-4E9E-9CC5-686C4B163116"
},
{
"criteria": "cpe:2.3:o:juniper:junos:16.1x65:d40:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46A11513-B901-4E12-8AA7-54D4794595D2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:17.2x75:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "191A3F26-3C6E-4B5A-9D40-E6ABC2BFA7AF"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:17.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F69A0E5-B61B-405D-B501-9CB306651CEA"
},
{
"criteria": "cpe:2.3:o:juniper:junos:17.3:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38A40E03-F915-4888-87B0-5950F75F097D"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:17.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "974B6128-ABD2-4D9C-87A1-5F1740DDCB95"
},
{
"criteria": "cpe:2.3:o:juniper:junos:17.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "988D317A-0646-491F-9B97-853E8E208276"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "sirt@juniper.net"
}