CVE-2017-2304
Summary
| CVE | CVE-2017-2304 |
|---|---|
| State | PUBLISHED |
| Assigner | juniper |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-30 14:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak' |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-200 | information leak
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | Ex4300 | - | All | All | All |
| Hardware | Juniper | Ex4600 | - | All | All | All |
| Operating System | Juniper | Junos | 14.1x53 | - | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d10 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d15 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d16 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d25 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d26 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d27 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d30 | All | All |
| Operating System | Juniper | Junos | 14.1x53 | d35 | All | All |
| Operating System | Juniper | Junos | 15.1 | - | All | All |
| Operating System | Juniper | Junos | 15.1 | r1 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | - | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d20 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d21 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d25 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d30 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d32 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d33 | All | All |
| Operating System | Juniper | Junos | 15.1x53 | d34 | All | All |
| Hardware | Juniper | Qfx3500 | - | All | All | All |
| Hardware | Juniper | Qfx3600 | - | All | All | All |
| Hardware | Juniper | Qfx5100 | - | All | All | All |
| Hardware | Juniper | Qfx5200 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Juniper Networks | Junos OS Running On QFX3500 QFX3600 QFX5100 QFX5200 EX4300 EX4600 Devices | affected 14.1X53 prior to 14.1X53-D40 | Not specified |
| CNA | Juniper Networks | Junos OS Running On QFX3500 QFX3600 QFX5100 QFX5200 EX4300 EX4600 Devices | affected 15.1X53 prior to 15.1X53-D40 | Not specified |
| CNA | Juniper Networks | Junos OS Running On QFX3500 QFX3600 QFX5100 QFX5200 EX4300 EX4600 Devices | affected 15.1 prior to 15.1R2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Juniper Products Ethernet Packet CVE-2017-2304 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Juniper Networks - 2017-01 Security Bulletin: QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600: 'Etherleak' memory disclosure in Ethernet padding data (CVE-2017-2304) | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | Vendor Advisory |
| Juniper Junos Ethernet Frame Padding Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.