PT-2021-3374 · Juniper Networks · Junos

Published

2021-04-14

·

Updated

2021-04-29

·

CVE-2021-0238

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions 17.3R1 through 17.4R3-S4 Junos OS versions 18.1 through 18.1R3-S12 Junos OS versions 18.2 through 18.2R3-S6 Junos OS versions 18.3 through 18.3R3-S3 Junos OS versions 18.4 through 18.4R3-S6 Junos OS versions 19.1 through 19.1R3-S3 Junos OS versions 19.2 through 19.2R1-S5 Junos OS versions 19.2 through 19.2R3-S1 Junos OS versions 19.3 through 19.3R3-S1 Junos OS versions 19.4 through 19.4R2-S3 Junos OS versions 19.4 through 19.4R3-S1 Junos OS versions 20.1 through 20.1R2 Junos OS versions 20.2 through 20.2R2-S2 Junos OS versions 20.2 through 20.2R2 Junos OS versions 20.3 through 20.3R1 Junos OS versions 20.4 through 20.4R0 Junos OS version 20.4R1
Description The issue is related to an uncontrolled resource consumption in Junos OS on MX Series routers. When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI commands may cause the system to run out of disk space. This can lead to other complications. Administrators can use the CLI command show system storage to monitor available disk space.
Recommendations For Junos OS versions 17.3R1 through 17.4R3-S4, update to version 17.4R3-S5 or later. For Junos OS versions 18.1 through 18.1R3-S12, update to version 18.1R3-S13 or later. For Junos OS versions 18.2 through 18.2R3-S6, update to version 18.2R3-S7 or later. For Junos OS versions 18.3 through 18.3R3-S3, update to version 18.3R3-S4 or later. For Junos OS versions 18.4 through 18.4R3-S6, update to version 18.4R3-S7 or later. For Junos OS versions 19.1 through 19.1R3-S3, update to version 19.1R3-S4 or later. For Junos OS versions 19.2 through 19.2R1-S5, update to version 19.2R1-S6 or later. For Junos OS versions 19.2 through 19.2R3-S1, update to version 19.2R3-S2 or later. For Junos OS versions 19.3 through 19.3R3-S1, update to version 19.3R3-S2 or later. For Junos OS versions 19.4 through 19.4R2-S3, update to version 19.4R2-S4 or later. For Junos OS versions 19.4 through 19.4R3-S1, update to version 19.4R3-S2 or later. For Junos OS versions 20.1 through 20.1R2, update to version 20.1R3 or later. For Junos OS versions 20.2 through 20.2R2-S2, update to version 20.2R2-S3 or later. For Junos OS versions 20.2 through 20.2R2, update to version 20.2R3 or later. For Junos OS versions 20.3 through 20.3R1, update to version 20.3R2 or later. For Junos OS versions 20.4 through 20.4R0, update to version 20.4R1-S1 or later. For Junos OS version 20.4R1, update to version 20.4R2 or later. As a temporary workaround, consider monitoring available disk space using the show system storage CLI command to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03225
CVE-2021-0238

Affected Products

Junos