SB2021011422 - Denial of serivce when processing DHCP traffic in Juniper Junos OS
Published: January 14, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2021-0217)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing DHCP packets from adjacent clients on EX Series and QFX Series switches. An attacker on the local network can send specially crafted HDCP packets to the affected system and exhaust DMA memory or crash the fxpc process.
Remediation
Install update from vendor's website.