PT-2021-12970 · Juniper Networks · Junos

Published

2021-04-22

·

Updated

2021-05-04

·

CVE-2021-0261

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions prior to 12.3R12-S17 on EX Series Junos OS versions prior to 12.3X48-D105 on SRX Series Junos OS versions prior to 15.1R7-S8 Junos OS versions prior to 15.1X49-D230 on SRX Series Junos OS versions prior to 16.1R7-S8 Junos OS versions prior to 17.4R2-S12 Junos OS versions prior to 17.4R3-S3 Junos OS versions prior to 18.1R3-S11 Junos OS versions prior to 18.2R3-S6 Junos OS versions prior to 18.3R2-S4 Junos OS versions prior to 18.3R3-S3 Junos OS versions prior to 18.4R2-S5 Junos OS versions prior to 18.4R3-S4 Junos OS versions prior to 19.1R2-S2 Junos OS versions prior to 19.1R3-S2 Junos OS versions prior to 19.2R1-S5 Junos OS versions prior to 19.2R3 Junos OS versions prior to 19.3R2-S4 Junos OS versions prior to 19.3R3 Junos OS versions prior to 19.4R1-S3 Junos OS versions prior to 19.4R2-S2 Junos OS versions prior to 19.4R3 Junos OS versions prior to 20.1R1-S3 Junos OS versions prior to 20.1R2 Junos OS versions prior to 20.2R1-S1 Junos OS versions prior to 20.2R2
Description: A vulnerability in the HTTP/HTTPS service allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for various services by sending a high number of specific requests. This issue affects several Juniper Networks Junos OS versions.
Recommendations: For Junos OS versions prior to 12.3R12-S17 on EX Series, update to 12.3R12-S17 or later. For Junos OS versions prior to 12.3X48-D105 on SRX Series, update to 12.3X48-D105 or later. For Junos OS versions prior to 15.1R7-S8, update to 15.1R7-S8 or later. For Junos OS versions prior to 15.1X49-D230 on SRX Series, update to 15.1X49-D230 or later. For Junos OS versions prior to 16.1R7-S8, update to 16.1R7-S8 or later. For Junos OS versions prior to 17.4R2-S12, update to 17.4R2-S12 or later. For Junos OS versions prior to 17.4R3-S3, update to 17.4R3-S3 or later. For Junos OS versions prior to 18.1R3-S11, update to 18.1R3-S11 or later. For Junos OS versions prior to 18.2R3-S6, update to 18.2R3-S6 or later. For Junos OS versions prior to 18.3R2-S4, update to 18.3R2-S4 or later. For Junos OS versions prior to 18.3R3-S3, update to 18.3R3-S3 or later. For Junos OS versions prior to 18.4R2-S5, update to 18.4R2-S5 or later. For Junos OS versions prior to 18.4R3-S4, update to 18.4R3-S4 or later. For Junos OS versions prior to 19.1R2-S2, update to 19.1R2-S2 or later. For Junos OS versions prior to 19.1R3-S2, update to 19.1R3-S2 or later. For Junos OS versions prior to 19.2R1-S5, update to 19.2R1-S5 or later. For Junos OS versions prior to 19.2R3, update to 19.2R3 or later. For Junos OS versions prior to 19.3R2-S4, update to 19.3R2-S4 or later. For Junos OS versions prior to 19.3R3, update to 19.3R3 or later. For Junos OS versions prior to 19.4R1-S3, update to 19.4R1-S3 or later. For Junos OS versions prior to 19.4R2-S2, update to 19.4R2-S2 or later. For Junos OS versions prior to 19.4R3, update to 19.4R3 or later. For Junos OS versions prior to 20.1R1-S3, update to 20.1R1-S3 or later. For Junos OS versions prior to 20.1R2, update to 20.1R2 or later. For Junos OS versions prior to 20.2R1-S1, update to 20.2R1-S1 or later. For Junos OS versions prior to 20.2R2, update to 20.2R2 or later.

Fix

DoS

Out of bounds Read

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-0261

Affected Products

Junos