PT-2021-12978 · Juniper Networks · Junos

Published

2021-04-22

·

Updated

2021-04-28

·

CVE-2021-0270

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions 18.1R2 through 18.1R3-S10
Description: A use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Juniper Networks Junos OS may allow an attacker to cause a Denial of Service (DoS) condition, leading to the restart of one or more Flexible PIC Concentrators (FPCs). This issue is more likely to occur during network instability, such as BGP/IGP reconvergences, or when there are more active traffic flows through the device. The restart of FPCs will cause traffic disruption and generate core files.
Recommendations: For Junos OS versions 18.1R2 through 18.1R3-S10, update to version 18.1R3-S10 or later to resolve the issue.

Fix

DoS

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-0270

Affected Products

Junos