PT-2021-2138 · Juniper Networks · Junos

Published

2021-01-13

·

Updated

2022-08-05

·

CVE-2021-0215

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions prior to 14.1X53-D54 Juniper Networks Junos OS versions prior to 15.1X49-D240 Juniper Networks Junos OS versions prior to 15.1X53-D593 Juniper Networks Junos OS versions prior to 16.1R7-S8 Juniper Networks Junos OS versions prior to 17.2R3-S4 Juniper Networks Junos OS versions prior to 17.3R3-S8 Juniper Networks Junos OS versions prior to 17.4R2-S11 Juniper Networks Junos OS versions prior to 17.4R3-S2 Juniper Networks Junos OS versions prior to 18.1R3-S10 Juniper Networks Junos OS versions prior to 18.2R2-S7 Juniper Networks Junos OS versions prior to 18.2R3-S3 Juniper Networks Junos OS versions prior to 18.3R2-S4 Juniper Networks Junos OS versions prior to 18.3R3-S2 Juniper Networks Junos OS versions prior to 18.4R1-S7 Juniper Networks Junos OS versions prior to 18.4R2-S4 Juniper Networks Junos OS versions prior to 18.4R3-S2 Juniper Networks Junos OS versions prior to 19.1R1-S5 Juniper Networks Junos OS versions prior to 19.1R2-S2 Juniper Networks Junos OS versions prior to 19.1R3 Juniper Networks Junos OS versions prior to 19.2R1-S5 Juniper Networks Junos OS versions prior to 19.2R2 Juniper Networks Junos OS versions prior to 19.3R2-S3 Juniper Networks Junos OS versions prior to 19.3R3 Juniper Networks Junos OS versions prior to 19.4R1-S2 Juniper Networks Junos OS versions prior to 19.4R2
Description A memory leak occurs every time the 802.1X authenticator port interface flaps, which can lead to other processes, such as the pfex process, responsible for packet forwarding, to crash and restart. This issue can be exploited by a remote attacker to cause a denial of service. An administrator can use the following CLI command to monitor the status of memory consumption: user@device> show task memory detail.
Recommendations For versions prior to 14.1X53-D54, update to 14.1X53-D54 or later. For versions prior to 15.1X49-D240, update to 15.1X49-D240 or later. For versions prior to 15.1X53-D593, update to 15.1X53-D593 or later. For versions prior to 16.1R7-S8, update to 16.1R7-S8 or later. For versions prior to 17.2R3-S4, update to 17.2R3-S4 or later. For versions prior to 17.3R3-S8, update to 17.3R3-S8 or later. For versions prior to 17.4R2-S11, update to 17.4R2-S11 or later. For versions prior to 17.4R3-S2, update to 17.4R3-S2 or later. For versions prior to 18.1R3-S10, update to 18.1R3-S10 or later. For versions prior to 18.2R2-S7, update to 18.2R2-S7 or later. For versions prior to 18.2R3-S3, update to 18.2R3-S3 or later. For versions prior to 18.3R2-S4, update to 18.3R2-S4 or later. For versions prior to 18.3R3-S2, update to 18.3R3-S2 or later. For versions prior to 18.4R1-S7, update to 18.4R1-S7 or later. For versions prior to 18.4R2-S4, update to 18.4R2-S4 or later. For versions prior to 18.4R3-S2, update to 18.4R3-S2 or later. For versions prior to 19.1R1-S5, update to 19.1R1-S5 or later. For versions prior to 19.1R2-S2, update to 19.1R2-S2 or later. For versions prior to 19.1R3, update to 19.1R3 or later. For versions prior to 19.2R1-S5, update to 19.2R1-S5 or later. For versions prior to 19.2R2, update to 19.2R2 or later. For versions prior to 19.3R2-S3, update to 19.3R2-S3 or later. For versions prior to 19.3R3, update to 19.3R3 or later. For versions prior to 19.4R1-S2, update to 19.4R1-S2 or later. For versions prior to 19.4R2, update to 19.4R2 or later.

Exploit

Fix

Memory Leak

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-00997
CVE-2021-0215

Affected Products

Junos