PT-2021-5114 · Juniper Networks · Junos

Published

2021-10-13

·

Updated

2021-10-25

·

CVE-2021-31351

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions 17.3R3-S11 through 17.4R3 prior to 17.4R3-S5 Juniper Networks Junos OS versions 18.1R3-S12 Juniper Networks Junos OS versions 18.2R2-S8 through 18.2R3-S8 Juniper Networks Junos OS versions 18.3R3-S4 Juniper Networks Junos OS versions 18.4R3-S7 Juniper Networks Junos OS versions 19.1R3-S4 through 19.1R3-S5 Juniper Networks Junos OS versions 19.2R1-S6 Juniper Networks Junos OS versions 19.3R3-S2 Juniper Networks Junos OS versions 19.4R2-S4 through 19.4R2-S5 Juniper Networks Junos OS versions 19.4R3-S2 Juniper Networks Junos OS versions 20.1R2-S1 Juniper Networks Junos OS versions 20.2R2-S2 through 20.2R3 Juniper Networks Junos OS versions 20.3R2 through 20.3R2-S1 Juniper Networks Junos OS versions 20.4R1 through 20.4R2 Juniper Networks Junos OS version 21.1R1
Description The issue is related to an improper check for unusual or exceptional conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS. This allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
Recommendations For Juniper Networks Junos OS versions 17.3R3-S11 through 17.4R3 prior to 17.4R3-S5, update to version 17.4R3-S5 or later. For Juniper Networks Junos OS versions 18.1R3-S12, update to a later version. For Juniper Networks Junos OS versions 18.2R2-S8 through 18.2R3-S8, update to a later version. For Juniper Networks Junos OS versions 18.3R3-S4, update to a later version. For Juniper Networks Junos OS versions 18.4R3-S7, update to a later version. For Juniper Networks Junos OS versions 19.1R3-S4 through 19.1R3-S5, update to a later version. For Juniper Networks Junos OS versions 19.2R1-S6, update to a later version. For Juniper Networks Junos OS versions 19.3R3-S2, update to a later version. For Juniper Networks Junos OS versions 19.4R2-S4 through 19.4R2-S5, update to a later version. For Juniper Networks Junos OS versions 19.4R3-S2, update to a later version. For Juniper Networks Junos OS versions 20.1R2-S1, update to a later version. For Juniper Networks Junos OS versions 20.2R2-S2 through 20.2R3, update to a later version. For Juniper Networks Junos OS versions 20.3R2 through 20.3R2-S1, update to a later version. For Juniper Networks Junos OS versions 20.4R1 through 20.4R2, update to a later version. For Juniper Networks Junos OS version 21.1R1, update to a later version. As a temporary workaround, consider restricting access to the MS-MPC/MS-MIC to minimize the risk of exploitation.

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05906
CVE-2021-31351

Affected Products

Junos