PT-2021-12978 · Juniper Networks · Junos
Published
2021-04-22
·
Updated
2021-04-28
·
CVE-2021-0270
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Junos OS versions 18.1R2 through 18.1R3-S10
Description:
A use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Juniper Networks Junos OS may allow an attacker to cause a Denial of Service (DoS) condition, leading to the restart of one or more Flexible PIC Concentrators (FPCs). This issue is more likely to occur during network instability, such as BGP/IGP reconvergences, or when there are more active traffic flows through the device. The restart of FPCs will cause traffic disruption and generate core files.
Recommendations:
For Junos OS versions 18.1R2 through 18.1R3-S10, update to version 18.1R3-S10 or later to resolve the issue.
Fix
DoS
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos