PT-2021-3986 · Juniper Networks · Junos
Published
2021-07-14
·
Updated
2022-04-26
·
CVE-2021-0285
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 15.1R7-S9
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.3R3-S11
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.4R2-S13
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 17.4R3-S5
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.3R3-S5
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.4R2-S8
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 18.4R3-S7
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.1R3-S5
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.2R1-S6
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.2R3-S2
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.3R2-S6
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.3R3-S2
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R1-S4
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R2-S4
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 19.4R3-S2
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.1R2-S2
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.1R3
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.2R2-S3
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.2R3
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.3R2
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.4R1-S1
Juniper Networks Junos OS on QFX5000 Series and EX4600 Series versions prior to 20.4R2
Description
The issue is related to an uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches. This vulnerability allows an attacker to cause Interchassis Control Protocol (ICCP) interruptions by sending large amounts of legitimate traffic, leading to an unstable control connection between the Multi-Chassis Link Aggregation Group (MC-LAG) nodes and potentially resulting in traffic loss. Continued receipt of this amount of traffic can create a sustained Denial of Service (DoS) condition. A log message indicating the system could be impacted by this issue is "DDOS PROTOCOL VIOLATION SET: Warning: Host-bound traffic for protocol/exception LOCALNH:aggregate exceeded its allowed bandwidth at fpc for times, started at ".
Recommendations
For versions 15.1, update to 15.1R7-S9 or later.
For versions 17.3, update to 17.3R3-S11 or later.
For versions 17.4, update to 17.4R2-S13 or 17.4R3-S5 or later.
For versions 18.3, update to 18.3R3-S5 or later.
For versions 18.4, update to 18.4R2-S8 or 18.4R3-S7 or later.
For versions 19.1, update to 19.1R3-S5 or later.
For versions 19.2, update to 19.2R1-S6 or 19.2R3-S2 or later.
For versions 19.3, update to 19.3R2-S6 or 19.3R3-S2 or later.
For versions 19.4, update to 19.4R1-S4 or 19.4R2-S4 or 19.4R3-S2 or later.
For versions 20.1, update to 20.1R2-S2 or 20.1R3 or later.
For versions 20.2, update to 20.2R2-S3 or 20.2R3 or later.
For versions 20.3, update to 20.3R2 or later.
For versions 20.4, update to 20.4R1-S1 or 20.4R2 or later.
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos