This KB article provides an explanation of the IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability (CVE-2016-1409).The customer is currently using the CVE ID workaround even though they are on the fixed version.
A vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet to be accepted by the router rather than discarded. The crafted packet, destined to the router, will then be processed by the routing engine (RE). A malicious network-based packet flood, sourced from beyond the local broadcast domain, can cause the RE CPU to spike, or cause the DDoS protection ARP protocol group policer to engage. When this happens, the DDoS policer may start dropping legitimate IPv6 neighbors as legitimate ND times out.Note that this is similar to the router's response to any purposeful malicious IPv6 ND flood destined to the router. The difference is that the crafted packet identified in the vulnerability is such that the forwarding controllers/ASICs should disallow this traffic from reaching the RE for further processing. Additionally, due to the routable nature of the crafted IPv6 ND packet, the attack may be launched from beyond the local broadcast domain.This issue only affects systems with IPv6 enabled. The attack vector for the vulnerability relies on IPv6 Neighbor Discovery processing. If IPv6 is not enabled, then this issue is not applicable.
Regarding the impact of the IPv6 Neighbor Discovery vulnerability published in JSA10749 [juniper.net] and tracked as CVE-2016-1409 on the QFX5200-32C running 18.4X29.
This advisory was released well before the QFX5200 platform existed. In fact, the earliest supported release We can find for the QFX5200-32C is 20.2R3, which was introduced nearly four years after the advisory was published.
Therefore, the customer can safely remove the CVE-2016-1409 mitigation from their QFX5200-32C switches running 18.4X29.
2025-11-30 : Article Published