#VU54915 Time-of-check Time-of-use (TOCTOU) Race Condition in Juniper Junos OS - CVE-2021-0289
Published: July 15, 2021
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to a race condition between the Device Control Daemon (DCD) and firewall process (dfwd) daemons of Juniper Networks Junos OS, when user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) interface units. A remote attacker on the local network can bypass the user-defined ARP Policer.