PT-2021-12942 · Juniper Networks · Junos
Published
2021-04-22
·
Updated
2021-04-27
·
CVE-2021-0229
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Juniper Networks Junos OS versions 16.1R1 through 17.3R3-S10
Juniper Networks Junos OS versions 17.4 through 17.4R2-S12
Juniper Networks Junos OS versions 18.1 through 18.1R3-S11
Juniper Networks Junos OS versions 18.2 through 18.2R2-S7
Juniper Networks Junos OS versions 18.3 through 18.3R3-S3
Juniper Networks Junos OS versions 18.4 through 18.4R1-S7
Juniper Networks Junos OS versions 19.1 through 19.1R3-S4
Juniper Networks Junos OS versions 19.2 through 19.2R1-S5
Juniper Networks Junos OS versions 19.3 through 19.3R3-S1
Juniper Networks Junos OS versions 19.4 through 19.4R2-S3
Juniper Networks Junos OS versions 20.1 through 20.1R2-S0
Juniper Networks Junos OS versions 20.2 through 20.2R2-S1
Juniper Networks Junos OS versions 20.3 through 20.3R1-S0
Description:
An uncontrolled resource consumption vulnerability in the Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker to cause the MQTT server to crash and restart, leading to a Denial of Service (DoS) by sending a stream of specific packets. A Juniper Extension Toolkit (JET) application designed with a listening port uses the MQTT protocol to connect to a mosquitto broker that is running on Junos OS to subscribe for events. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
Recommendations:
For Juniper Networks Junos OS versions 16.1R1 through 17.3R3-S10, update to version 17.3R3-S11 or later.
For Juniper Networks Junos OS versions 17.4 through 17.4R2-S12, update to version 17.4R2-S13 or later.
For Juniper Networks Junos OS versions 18.1 through 18.1R3-S11, update to version 18.1R3-S12 or later.
For Juniper Networks Junos OS versions 18.2 through 18.2R2-S7, update to version 18.2R2-S8 or later.
For Juniper Networks Junos OS versions 18.3 through 18.3R3-S3, update to version 18.3R3-S4 or later.
For Juniper Networks Junos OS versions 18.4 through 18.4R1-S7, update to version 18.4R1-S8 or later.
For Juniper Networks Junos OS versions 19.1 through 19.1R3-S4, update to version 19.1R3-S5 or later.
For Juniper Networks Junos OS versions 19.2 through 19.2R1-S5, update to version 19.2R1-S6 or later.
For Juniper Networks Junos OS versions 19.3 through 19.3R3-S1, update to version 19.3R3-S2 or later.
For Juniper Networks Junos OS versions 19.4 through 19.4R2-S3, update to version 19.4R2-S4 or later.
For Juniper Networks Junos OS versions 20.1 through 20.1R2-S0, update to version 20.1R2-S1 or later.
For Juniper Networks Junos OS versions 20.2 through 20.2R2-S1, update to version 20.2R2-S2 or later.
For Juniper Networks Junos OS versions 20.3 through 20.3R1-S0, update to version 20.3R1-S1 or later.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos