A vulnerability in processing Secure Neighbor Discovery (SEND) Protocol packets can result in a high CPU consumption denial of service condition on Junos devices. Transit traffic is unaffected, but CLI responsiveness and processing of IPv6 packets via the link-local addresses may be impacted. The issue can occur only when the Secure Neighbor Discovery feature has been configured via the ' set protocols neighbor-discovery secure security-level default ' option. This issue was discovered by an external security researcher. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue. This issue has been assigned CVE-2015-5360 .
set protocols neighbor-discovery secure security-level default
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X44-D51, 12.1X46-D36, 12.1X46-D45*, 12.1X47-D25, 12.3R10, 12.3X48-D20, 13.2R8, 13.3R6, 14.1R5, 14.2R3, 15.1R1, 15.1X49-D20, and all subsequent releases. This issue is being tracked as PR 1055018 and is visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies. *12.1X46-D45 will be available after 06-Jan-2016.
If Secure Neighbor Discovery is not required, disabling ' neighbor-discovery secure ' within the ' protocols ' configuration hierarchy will mitigate this issue.
neighbor-discovery secure
protocols
2015-07-08: Initial publication 2015-07-22: Added clarification of partial availability impact 2015-11-20: Clarified 12.1X46-D45 fixed release and availability date
The Juniper SIRT would like to acknowledge and thank Daniel Edwards of Microsoft Corporation for responsibly reporting this vulnerability.