Improper Check for Unusual or Exceptional Conditions in Junos OS and Junos OS Evolved - CVE-2021-0236
Published: April 16, 2021
Vulnerability details
The vulnerability allows a remote user to perform denial of service attack.
The vulnerability exists due to improper check for unusual or exceptional conditions within the Routing Protocol Daemon (RPD) service when handling BGP VPNv6 flowspec messages. A remote user attacker can send specific matching BGP packet, which meets a specific term in the flowspec configuration and crash the service.
Affected software
Junos OS Evolved
How to mitigate CVE-2021-0236
Junos OS Evolved - addressed in versions 20.3R2-EVO, 20.4R1-EVO