Back to overview

CVE-2021-0211

CRITICAL
10.0
CVSS 3.1
Description
An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3-S1; 19.4 versions prior to 19.4R1-S3, 19.4R2-S3, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S3 20.2R2; 20.3 versions prior to 20.3R1-S1, 20.3R2. Junos OS Evolved: All versions prior to 20.3R1-S1-EVO, 20.3R2-EVO.

Metadata

CVE ID
CVE-2021-0211
State
PUBLISHED
Assigner
juniper
Reserved
2020-10-27 00:00 UTC
Published
2021-01-15 17:35 UTC
Last updated
2024-09-16 20:52 UTC
Vendor / Product
Juniper Networks / Junos OS
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Affected products (4)
VendorProductPlatformVersions
Juniper Networks Junos OS EX Series 15.1 < 15.1R7-S8
Juniper Networks Junos OS 17.3 < 17.3R3-S10, 17.4 < 17.4R2-S12, 17.4R3-S4, 18.1 < 18.1R3-S12, 18.2 < 18.2R2-S8, 18.2R3-S6 …
Juniper Networks Junos OS SRX Series 15.1X49 < 15.1X490-D240
Juniper Networks Junos OS Evolved unspecified < 20.3R1-S1-EVO, 20.3R2-EVO
Weakness (CWE)
CWESourceDescription
cna 754 - Improper Check for Unusual or Exceptional Conditions
cna Denial of Service (DoS)
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Back to overview