PT-2021-3986 · Juniper Networks · Junos

Published

2021-07-14

·

Updated

2022-04-26

·

CVE-2021-0285

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 15.1R7-S9 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.3R3-S11 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.4R2-S13 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.4R3-S5 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.3R3-S5 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.4R2-S8 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.4R3-S7 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.1R3-S5 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.2R1-S6 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.2R3-S2 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.3R2-S6 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.3R3-S2 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R1-S4 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R2-S4 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R3-S2 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.1R2-S2 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.1R3 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.2R2-S3 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.2R3 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.3R2 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.4R1-S1 Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.4R2
Description The issue is related to an uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches. This vulnerability allows an attacker to cause Interchassis Control Protocol (ICCP) interruptions by sending large amounts of legitimate traffic, leading to an unstable control connection between the Multi-Chassis Link Aggregation Group (MC-LAG) nodes and potentially resulting in traffic loss. Continued receipt of this amount of traffic can create a sustained Denial of Service (DoS) condition. A log message indicating the system could be impacted by this issue is "DDOS PROTOCOL VIOLATION SET: Warning: Host-bound traffic for protocol/exception LOCALNH:aggregate exceeded its allowed bandwidth at fpc for times, started at ".
Recommendations For versions 15.1, update to 15.1R7-S9 or later. For versions 17.3, update to 17.3R3-S11 or later. For versions 17.4, update to 17.4R2-S13 or 17.4R3-S5 or later. For versions 18.3, update to 18.3R3-S5 or later. For versions 18.4, update to 18.4R2-S8 or 18.4R3-S7 or later. For versions 19.1, update to 19.1R3-S5 or later. For versions 19.2, update to 19.2R1-S6 or 19.2R3-S2 or later. For versions 19.3, update to 19.3R2-S6 or 19.3R3-S2 or later. For versions 19.4, update to 19.4R1-S4 or 19.4R2-S4 or 19.4R3-S2 or later. For versions 20.1, update to 20.1R2-S2 or 20.1R3 or later. For versions 20.2, update to 20.2R2-S3 or 20.2R3 or later. For versions 20.3, update to 20.3R2 or later. For versions 20.4, update to 20.4R1-S1 or 20.4R2 or later.

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04507
CVE-2021-0285

Affected Products

Junos