← Vulnerability feed

Vulnerability record · CVE-2018-0014 · published 10 January 2018

CVE-2018-0014: Juniper screenos information exposure vulnerability

Juniper · Screenos

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.

6.5 CVSS 3.0 Medium EPSS 0.60% · top 53.3% CWE-200 · Information exposure
6.5CVSS 3.0 base score, v2 3.3
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securitytracker.com/id/1040185 Third Party AdvisoryVDB Entry
https://kb.juniper.net/JSA10841 Vendor Advisory
http://www.securitytracker.com/id/1040185 Third Party AdvisoryVDB Entry
https://kb.juniper.net/JSA10841 Vendor Advisory

Track CVE-2018-0014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7755Juniper ScreenOS improper authentication grants admin accessJuniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants adm…KEVEPSS 61%analysed8.1CVE-2015-7754Juniper screenos improper input validation vulnerabilityJuniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or exec…EPSS 3.9%7.8CVE-2014-3813Juniper screenos vulnerabilityUnspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lo…EPSS 1.3%7.8CVE-2014-3814Juniper screenos improper input validation vulnerabilityThe Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote att…EPSS 1.3%7.8CVE-2014-2842Juniper screenos vulnerabilityJuniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.EPSS 3.5%7.5CVE-2016-1268Juniper screenos improper input validation vulnerabilityThe administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra…EPSS 1.9%7.1CVE-2013-6958Juniper screenos vulnerabilityJuniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of…EPSS 1.9%5.4CVE-2017-2337Juniper screenos cross-site scripting vulnerabilityA persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-0014), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.