SB2021041603 - Denial of service when handling BGP VPNv6 flowspec messages in Juniper Junos OS and OS Evolved



SB2021041603 - Denial of service when handling BGP VPNv6 flowspec messages in Juniper Junos OS and OS Evolved

Published: April 16, 2021

Security Bulletin ID SB2021041603
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2021-0236)

The vulnerability allows a remote user to perform denial of service attack.

The vulnerability exists due to improper check for unusual or exceptional conditions within the Routing Protocol Daemon (RPD) service when handling BGP VPNv6 flowspec messages. A remote user attacker can send specific matching BGP packet, which meets a specific term in the flowspec configuration and crash the service.


Remediation

Install update from vendor's website.