PT-2021-12955 · Juniper Networks · Junos
Published
2021-04-22
·
Updated
2021-04-28
·
CVE-2021-0244
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Juniper Networks Junos OS versions prior to 14.1X53-D49 on EX Series
Juniper Networks Junos OS versions prior to 15.1R7-S6
Juniper Networks Junos OS versions prior to 15.1X49-D191, 15.1X49-D200 on SRX Series
Juniper Networks Junos OS versions prior to 16.1R7-S7
Juniper Networks Junos OS versions prior to 16.2R2-S11, 16.2R3
Juniper Networks Junos OS versions prior to 17.1R2-S11, 17.1R3
Juniper Networks Junos OS versions prior to 17.2R2-S8, 17.2R3-S3
Juniper Networks Junos OS versions prior to 17.3R2-S5, 17.3R3-S7
Juniper Networks Junos OS versions prior to 17.4R2-S9, 17.4R3
Juniper Networks Junos OS versions prior to 18.1R3-S5
Juniper Networks Junos OS versions prior to 18.2R2-S6, 18.2R3
Juniper Networks Junos OS versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3
Juniper Networks Junos OS versions prior to 18.4R1-S5, 18.4R2
Juniper Networks Junos OS versions prior to 19.1R1-S4, 19.1R2
Description:
A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS, which may allow an attacker to bypass the storm-control feature on devices. This issue occurs during specific actions taken by an administrator under certain conditions and is more frequent on devices configured in Virtual Chassis configurations. An Indicator of Compromise (IoC) may be seen by reviewing log files for the error message '/kernel: GENCFG: op 58 (Storm Control Blob) failed; err 1 (Unknown)'.
Recommendations:
For Juniper Networks Junos OS versions prior to 14.1X53-D49 on EX Series, update to version 14.1X53-D49 or later.
For Juniper Networks Junos OS versions prior to 15.1R7-S6, update to version 15.1R7-S6 or later.
For Juniper Networks Junos OS versions prior to 15.1X49-D191, 15.1X49-D200 on SRX Series, update to version 15.1X49-D191, 15.1X49-D200 or later.
For Juniper Networks Junos OS versions prior to 16.1R7-S7, update to version 16.1R7-S7 or later.
For Juniper Networks Junos OS versions prior to 16.2R2-S11, 16.2R3, update to version 16.2R2-S11, 16.2R3 or later.
For Juniper Networks Junos OS versions prior to 17.1R2-S11, 17.1R3, update to version 17.1R2-S11, 17.1R3 or later.
For Juniper Networks Junos OS versions prior to 17.2R2-S8, 17.2R3-S3, update to version 17.2R2-S8, 17.2R3-S3 or later.
For Juniper Networks Junos OS versions prior to 17.3R2-S5, 17.3R3-S7, update to version 17.3R2-S5, 17.3R3-S7 or later.
For Juniper Networks Junos OS versions prior to 17.4R2-S9, 17.4R3, update to version 17.4R2-S9, 17.4R3 or later.
For Juniper Networks Junos OS versions prior to 18.1R3-S5, update to version 18.1R3-S5 or later.
For Juniper Networks Junos OS versions prior to 18.2R2-S6, 18.2R3, update to version 18.2R2-S6, 18.2R3 or later.
For Juniper Networks Junos OS versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3, update to version 18.3R1-S7, 18.3R2-S3, 18.3R3 or later.
For Juniper Networks Junos OS versions prior to 18.4R1-S5, 18.4R2, update to version 18.4R1-S5, 18.4R2 or later.
For Juniper Networks Junos OS versions prior to 19.1R1-S4, 19.1R2, update to version 19.1R1-S4, 19.1R2 or later.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos