PT-2021-5388 · Juniper Networks · Junos+1
Published
2021-10-13
·
Updated
2021-10-25
·
CVE-2021-31383
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 19.2R3-S2, 19.3R2-S6, 19.3R3-S2, 19.4R1-S4, 19.4R2-S4, 19.4R3-S3, 20.1R2-S2, 20.1R3, 20.2R2-S3, 20.2R3, 20.3R2
Juniper Networks Junos OS Evolved versions prior to 20.1R3-EVO, 20.2R3-EVO, 20.3R2-EVO
Description
The issue is related to the improper use of a source to destination copy operation combined with a Stack-based Buffer Overflow in the Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors. This can cause the routing protocol daemon (RPD) to crash, resulting in a Denial of Service (DoS) when certain specific packets are processed. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. The issue can be exploited by a remote unauthenticated network attacker.
Recommendations
For Juniper Networks Junos OS versions prior to 19.2R3-S2, update to version 19.2R3-S2 or later.
For Juniper Networks Junos OS versions prior to 19.3R2-S6, update to version 19.3R2-S6 or later.
For Juniper Networks Junos OS versions prior to 19.3R3-S2, update to version 19.3R3-S2 or later.
For Juniper Networks Junos OS versions prior to 19.4R1-S4, update to version 19.4R1-S4 or later.
For Juniper Networks Junos OS versions prior to 19.4R2-S4, update to version 19.4R2-S4 or later.
For Juniper Networks Junos OS versions prior to 19.4R3-S3, update to version 19.4R3-S3 or later.
For Juniper Networks Junos OS versions prior to 20.1R2-S2, update to version 20.1R2-S2 or later.
For Juniper Networks Junos OS versions prior to 20.1R3, update to version 20.1R3 or later.
For Juniper Networks Junos OS versions prior to 20.2R2-S3, update to version 20.2R2-S3 or later.
For Juniper Networks Junos OS versions prior to 20.2R3, update to version 20.2R3 or later.
For Juniper Networks Junos OS versions prior to 20.3R2, update to version 20.3R2 or later.
For Juniper Networks Junos OS Evolved versions prior to 20.1R3-EVO, update to version 20.1R3-EVO or later.
For Juniper Networks Junos OS Evolved versions prior to 20.2R3-EVO, update to version 20.2R3-EVO or later.
For Juniper Networks Junos OS Evolved versions prior to 20.3R2-EVO, update to version 20.3R2-EVO or later.
Fix
DoS
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos
Junos Evolved