Improper Check for Unusual or Exceptional Conditions in Junos OS Evolved - CVE-2021-0225

 

Improper Check for Unusual or Exceptional Conditions in Junos OS Evolved - CVE-2021-0225

Published: April 16, 2021


Vulnerability identifier: #VU52307
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0225
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the stateless IP firewall filter does not work as expected. A remote attacker can cause the stateless firewall filter configuration which uses the action "policer" in certain combinations with other options to not take effect.


Affected software

Junos OS Evolved

How to mitigate CVE-2021-0225

Install updates from vendor's website.

Junos OS Evolved - addressed in versions 20.3R1-S2-EVO, 20.3R2-EVO, 20.4R1-EVO

External References

Related Security Bulletins