SB2021011812 - Denial of service in Storm Control feature in Juniper Junos OS



SB2021011812 - Denial of service in Storm Control feature in Juniper Junos OS

Published: January 18, 2021

Security Bulletin ID SB2021011812
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2021-0203)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources on Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG). The Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. A remote attacker can perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.