#VU49548 Resource exhaustion in Juniper Junos OS - CVE-2021-0217

 

#VU49548 Resource exhaustion in Juniper Junos OS - CVE-2021-0217

Published: January 14, 2021


Vulnerability identifier: #VU49548
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-0217
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Juniper Junos OS
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing DHCP packets from adjacent clients on EX Series and QFX Series switches. An attacker on the local network can send specially crafted HDCP packets to the affected system and exhaust DMA memory or crash the fxpc process.


Remediation

Install updates from vendor's website.

This issue affects Juniper Networks Junos OS on EX Series and QFX Series:

  • 17.4R3 versions prior to 17.4R3-S3;
  • 18.1R3 versions between 18.1R3-S6 and 18.1R3-S11;
  • 18.2R3 versions prior to 18.2R3-S6;
  • 18.3R3 versions prior to 18.3R3-S4;
  • 18.4R2 versions prior to 18.4R2-S5;
  • 18.4R3 versions prior to 18.4R3-S6;
  • 19.1 versions between 19.1R2 and 19.1R3-S3;
  • 19.2 versions prior to 19.2R3-S1;
  • 19.3 versions prior to 19.3R2-S5, 19.3R3;
  • 19.4 versions prior to 19.4R2-S2, 19.4R3;
  • 20.1 versions prior to 20.1R2;
  • 20.2 versions prior to 20.2R1-S2, 20.2R2.

Junos OS versions prior to 17.4R3 are unaffected by this vulnerability.


External links