PT-2021-3310 · Juniper Networks · Junos

Published

2021-04-14

·

Updated

2022-08-05

·

CVE-2021-0257

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 17.3R3-S10 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 17.4R3-S3 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 18.2R3-S7 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 18.3R3-S4 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 18.4R3-S6 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 19.2R3-S2 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 19.3R3-S1 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 19.4R2-S2, 19.4R3 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 20.2R1-S3, 20.2R2 Juniper Networks Junos OS on MX Series, EX9200 Series versions prior to 20.3R1-S1, 20.3R2
Description The issue is related to memory leaks in the Modular Port Concentrator (MPC) of Provider Edge (PE) devices, which can cause an out of memory condition and MPC restart. This occurs when certain Layer 2 network events at Customer Edge (CE) devices happen, and Integrated Routing and Bridging (IRB) interfaces are configured and mapped to a VPLS instance or a Bridge-Domain. An administrator can use the CLI command show system resource-monitor fpc to monitor the status of memory usage level of the MPC. When the issue occurs, there will be temporary traffic interruption until the MPC is restored.
Recommendations For versions prior to 17.3R3-S10, update to 17.3R3-S10 or later. For versions prior to 17.4R3-S3, update to 17.4R3-S3 or later. For versions prior to 18.2R3-S7, update to 18.2R3-S7 or later. For versions prior to 18.3R3-S4, update to 18.3R3-S4 or later. For versions prior to 18.4R3-S6, update to 18.4R3-S6 or later. For versions prior to 19.2R3-S2, update to 19.2R3-S2 or later. For versions prior to 19.3R3-S1, update to 19.3R3-S1 or later. For versions prior to 19.4R2-S2, 19.4R3, update to 19.4R2-S2, 19.4R3 or later. For versions prior to 20.2R1-S3, 20.2R2, update to 20.2R1-S3, 20.2R2 or later. For versions prior to 20.3R1-S1, 20.3R2, update to 20.3R1-S1, 20.3R2 or later. As a temporary workaround, consider monitoring the memory usage level of the MPC using the show system resource-monitor fpc CLI command to detect potential issues before they cause an MPC restart.

Fix

Resource Exhaustion

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2021-03087
CVE-2021-0257

Affected Products

Junos