PT-2021-5047 · Juniper Networks · Junos

Published

2021-10-13

·

Updated

2021-10-25

·

CVE-2021-31376

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096 versions 18.4R3-S7 through 18.4R3-S8
Description An Improper Input Validation vulnerability in the Packet Forwarding Engine manager (FXPC) process allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Continued receipt and processing of this specific packet will create a sustained Denial of Service (DoS) condition.
Recommendations For Juniper Networks Junos OS on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096 version 18.4R3-S7 and later versions prior to 18.4R3-S8, update to version 18.4R3-S8 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable FXPC service until a patch is available. Avoid sending specific DHCPv6 packets to the device to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05817
CVE-2021-31376

Affected Products

Junos