PT-2021-2138 · Juniper Networks · Junos
Published
2021-01-13
·
Updated
2022-08-05
·
CVE-2021-0215
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 14.1X53-D54
Juniper Networks Junos OS versions prior to 15.1X49-D240
Juniper Networks Junos OS versions prior to 15.1X53-D593
Juniper Networks Junos OS versions prior to 16.1R7-S8
Juniper Networks Junos OS versions prior to 17.2R3-S4
Juniper Networks Junos OS versions prior to 17.3R3-S8
Juniper Networks Junos OS versions prior to 17.4R2-S11
Juniper Networks Junos OS versions prior to 17.4R3-S2
Juniper Networks Junos OS versions prior to 18.1R3-S10
Juniper Networks Junos OS versions prior to 18.2R2-S7
Juniper Networks Junos OS versions prior to 18.2R3-S3
Juniper Networks Junos OS versions prior to 18.3R2-S4
Juniper Networks Junos OS versions prior to 18.3R3-S2
Juniper Networks Junos OS versions prior to 18.4R1-S7
Juniper Networks Junos OS versions prior to 18.4R2-S4
Juniper Networks Junos OS versions prior to 18.4R3-S2
Juniper Networks Junos OS versions prior to 19.1R1-S5
Juniper Networks Junos OS versions prior to 19.1R2-S2
Juniper Networks Junos OS versions prior to 19.1R3
Juniper Networks Junos OS versions prior to 19.2R1-S5
Juniper Networks Junos OS versions prior to 19.2R2
Juniper Networks Junos OS versions prior to 19.3R2-S3
Juniper Networks Junos OS versions prior to 19.3R3
Juniper Networks Junos OS versions prior to 19.4R1-S2
Juniper Networks Junos OS versions prior to 19.4R2
Description
A memory leak occurs every time the 802.1X authenticator port interface flaps, which can lead to other processes, such as the
pfex process, responsible for packet forwarding, to crash and restart. This issue can be exploited by a remote attacker to cause a denial of service. An administrator can use the following CLI command to monitor the status of memory consumption: user@device> show task memory detail.Recommendations
For versions prior to 14.1X53-D54, update to 14.1X53-D54 or later.
For versions prior to 15.1X49-D240, update to 15.1X49-D240 or later.
For versions prior to 15.1X53-D593, update to 15.1X53-D593 or later.
For versions prior to 16.1R7-S8, update to 16.1R7-S8 or later.
For versions prior to 17.2R3-S4, update to 17.2R3-S4 or later.
For versions prior to 17.3R3-S8, update to 17.3R3-S8 or later.
For versions prior to 17.4R2-S11, update to 17.4R2-S11 or later.
For versions prior to 17.4R3-S2, update to 17.4R3-S2 or later.
For versions prior to 18.1R3-S10, update to 18.1R3-S10 or later.
For versions prior to 18.2R2-S7, update to 18.2R2-S7 or later.
For versions prior to 18.2R3-S3, update to 18.2R3-S3 or later.
For versions prior to 18.3R2-S4, update to 18.3R2-S4 or later.
For versions prior to 18.3R3-S2, update to 18.3R3-S2 or later.
For versions prior to 18.4R1-S7, update to 18.4R1-S7 or later.
For versions prior to 18.4R2-S4, update to 18.4R2-S4 or later.
For versions prior to 18.4R3-S2, update to 18.4R3-S2 or later.
For versions prior to 19.1R1-S5, update to 19.1R1-S5 or later.
For versions prior to 19.1R2-S2, update to 19.1R2-S2 or later.
For versions prior to 19.1R3, update to 19.1R3 or later.
For versions prior to 19.2R1-S5, update to 19.2R1-S5 or later.
For versions prior to 19.2R2, update to 19.2R2 or later.
For versions prior to 19.3R2-S3, update to 19.3R2-S3 or later.
For versions prior to 19.3R3, update to 19.3R3 or later.
For versions prior to 19.4R1-S2, update to 19.4R1-S2 or later.
For versions prior to 19.4R2, update to 19.4R2 or later.
Exploit
Fix
Memory Leak
Missing Release of Resource after Effective Lifetime
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos