Security readout for executives and security teams
Plain-English summary
Some Juniper Junos OS devices in MPLS environments can have their routing daemon crash after receiving a specific SNMP packet. Repeated packets could keep routing unstable and cause a prolonged denial of service. The issue is availability-only, but routing outages can directly affect business connectivity.
Executive priority
Treat as a high-priority network availability issue for MPLS environments. It does not indicate data theft, but repeated routing daemon crashes can disrupt business connectivity. Prioritize exposed Juniper infrastructure that supports critical network paths.
Technical view
CVE-2019-0043 is a Junos OS RPD crash condition triggered by a specific SNMP packet in MPLS environments. CVSS 3.0 is 7.5: network-reachable, low complexity, no privileges, no user interaction, high availability impact, no confidentiality or integrity impact. CWE-404 is listed.
Likely exposure
Exposure is most likely on Juniper SRX, EX, QFX, ACX, and NFX devices running the listed vulnerable Junos OS releases in MPLS environments where SNMP can reach the device. The bundle states no other Juniper products or platforms are affected.
Exploitation context
The provided sources do not show CISA KEV listing or active exploitation. The described attack condition is repeated delivery of a specific SNMP packet causing repeated RPD crashes and restart cycles. Evidence is sufficient for denial-of-service risk, not for confirmed exploitation in the wild.
Researcher notes
The key scoping constraints are Junos OS, MPLS environment, specific affected release trains, and SNMP packet handling leading to RPD crash. The source bundle provides fixed-version thresholds but does not provide exploit proof, packet details, or evidence of active exploitation.
Mitigation direction
- Identify Junos OS devices running affected release trains listed in the advisory.
- Prioritize upgrades to fixed Junos OS releases named by Juniper.
- Check Juniper JSA10935 for current vendor guidance and any operational workarounds.
- Restrict SNMP reachability to authorized management paths where consistent with existing policy.
- Monitor routing daemon restarts until vulnerable systems are upgraded.
Validation and detection
- Inventory Junos OS version, platform family, and MPLS use across network devices.
- Compare installed versions with the affected and fixed releases in JSA10935.
- Review SNMP exposure for affected devices without testing exploit traffic.
- Check logs and monitoring for unexpected RPD restarts or routing instability.
- Confirm post-upgrade versions are at or beyond Juniper fixed releases.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-404: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2019-0043 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
7.5HighVector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.juniper.net/JSA10935CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Resource Shutdown or Release
Improper Resource Shutdown or Release represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
