Additional examples from ongoing research have resulted in the following significant findings:
*High End SRX Series devices are not vulnerable to this exploit.
Affected releases are Juniper Networks Junos OS:
No other Juniper Networks products or platforms are affected by this issue.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during an external security research.
This issue has been assigned CVE-2018-0007 .
The following software releases have been updated to resolve this specific issue: 12.1X46-D71, 12.3X48-D55, 12.3R12-S7, 12.3X48-D55, 14.1R8-S5, 14.1R9, 14.1X53-D46, 14.2R7-S9, 14.2R8, 15.1F2-S17, 15.1F5-S8, 15.1F6-S8, 15.1R7, 15.1X49-D90, 15.1X53-D65, 16.1R4-S6, 16.1R5, 16.1X65-D45, 16.2R2, 17.1R2, 17.2R1, and all subsequent releases.
KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
This issue is being tracked as 1252823 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
set system processes lldpd-service disable
set system processes l2cpd-service disable
Additional protocols L2CPD daemon supports include RSTP, MSTP, VSTP, ERP, xSTP and ERP protocols. After issuing set system processes l2cpd-service disable , RSTP, MSTP, VSTP, ERP, xSTP and ERP protocols will cease to operate. Please note, this is not an exhaustive list, disabling L2CPD may affect other protocols and services that rely upon L2CPD daemon to be present. For example, L2ALD, MRVP, EVPN traffic, etc. may also cease to operate. To avoid downtime, customers considering applying this workaround should carefully test all workaround changes to their environment in a non-production environment first that mirrors or as closely as possible matches the production environment before applying to the production environment. 2. Configure target interfaces on the device to disable LLDP packet processing: Set protocols lldp interface <interface name> disable 3. On Switching platforms such as EX/QFX Series devices implement packet filters to discard LLDP packets with an EtherType of 0x88cc. For example: set firewall family ethernet-switching filter LLDP_EXAMPLE term 1 from ether-type 0x88cc set firewall family ethernet-switching filter LLDP_EXAMPLE term 1 then discard Workaround #3 does not work on MX Series devices. MX Series devices should disable LLDP processing, filter off-system, or upgrade to a fixed release. 4. Lastly, as a method to reduce the risk of exploitation for this vulnerability, customers may implement off-system IDP and/or Firewall filtering methods such as disallowing LLDP EtherType to propagate completely on local segments, or by filtering broadcast addressed LLDP packets or unicast addressed LLDP packets not originated from trusted sources targeted to trusted destinations. Additionally, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device via all means to only trusted, administrative networks, hosts and users.
Set protocols lldp interface <interface name> disable
0x88cc.
set firewall family ethernet-switching filter LLDP_EXAMPLE term 1 from ether-type 0x88cc set firewall family ethernet-switching filter LLDP_EXAMPLE term 1 then discard
2018-01-10: Initial publication 2018-01-11: Added CLI config stanza to disable LLDP daemon as workaround. Added SRX-Series into affected. SRX HE is unaffected. 2018-01-12: Added clear detail that SRX HE is unaffected at top in description as example, configuration stanza is not required for exploitability, only presence of daemon(s) running on system. 2018-01-17: Removed 14.1X53-D50; this is not a valid release. 2018-02-05: Updated JSA for clarification around routing, switching and security platforms; as well as additional test details resulting in findings for these platforms. 2018-02-14: Updated JSA for clarification on findings to MX Series. Updated JSA to read "CPU" instead of "Memory" for DoS impact to EX Series devices. Updated the workaround section for LLDPD and L2CPD CLI stanza, and to filter Broadcast addressed LLDP on network as a workaround. 2018-03-01: Updated problem and workaround solution to clarify affected methods; new CVSS scores and workaround examples for various platform. Separated the HE to still unaffected, vSRX with L2CPD and Branch SRX to LLDPD 2018-03-06: Minor language modifications for clarity. 2018-03-14: Minor update to workaround impact for disabling L2CPD.
We would like to would like to acknowledge and thank,