CRITICAL🇬🇧 English

CVE-2021-0211

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVSS 10.0v3.1pub. 2021-01-15upd. 2024-11-21

Podatność w usłudze Routing Protocol Daemon (RPD) systemów Juniper Networks Junos OS i Junos OS Evolved umożliwia atakującemu wywołanie Denial of Service (DoS) poprzez wysłanie poprawnego komunikatu BGP FlowSpec. Podatność posiada ocenę CVSS 10.0, co czyni ją krytyczną.

Pokaż oryginał (EN)

An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3-S1; 19.4 versions prior to 19.4R1-S3, 19.4R2-S3, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S3 20.2R2; 20.3 versions prior to 20.3R1-S1, 20.3R2. Junos OS Evolved: All versions prior to 20.3R1-S1-EVO, 20.3R2-EVO.

🤖 Analiza AI
Jak działa

Usługa RPD nie sprawdza prawidłowo nietypowych lub wyjątkowych warunków podczas przetwarzania komunikatów BGP FlowSpec (CWE-754). Atakujący może wysłać poprawny (ale spreparowany) komunikat BGP FlowSpec, który powoduje nieoczekiwaną zmianę w rozgłaszaniu tras w domenie BGP FlowSpec. Skutkuje to zakłóceniami w przepływie ruchu sieciowego. Ciągłe dostarczanie takich komunikatów podtrzymuje stan DoS przez cały czas ich napływania.

Skutki

Atakujący zdalny i nieuwierzytelniony może trwale zakłócić przepływ ruchu sieciowego w domenie BGP FlowSpec, powodując stan Denial of Service (DoS). Nie stwierdzono bezpośredniego zagrożenia dla poufności danych, jednak integralność i dostępność sieci są poważnie naruszone.

Mitygacja

Należy zaktualizować oprogramowanie do wersji zawierających poprawkę: Junos OS 17.3R3-S10, 17.4R2-S12 / 17.4R3-S4, 18.1R3-S12, 18.2R2-S8 / 18.2R3-S6, 18.3R3-S4, 18.4R1-S8 / 18.4R2-S6 / 18.4R3-S6, 19.1R1-S6 / 19.1R2-S2 / 19.1R3-S3, 19.2R3-S1, 19.3R2-S5 / 19.3R3-S1, 19.4R1-S3 / 19.4R2-S3 / 19.4R3, 20.1R2, 20.2R1-S3 / 20.2R2, 20.3R1-S1 / 20.3R2; dla Junos OS Evolved: 20.3R1-S1-EVO lub 20.3R2-EVO. Szczegóły dostępne pod adresem: https://kb.juniper.net/JSA11101.

Kogo dotyczy

Juniper Networks Junos OS: wszystkie wersje wcześniejsze niż 17.3R3-S10 (z wyjątkiem 15.1X49-D240 na SRX Series i 15.1R7-S8 na EX Series); gałęzie 17.3, 17.4, 18.1, 18.2, 18.3, 18.4, 19.1, 19.2, 19.3, 19.4, 20.1, 20.2, 20.3 przed określonymi wersjami patcha; Junos OS Evolved: wszystkie wersje wcześniejsze niż 20.3R1-S1-EVO i 20.3R2-EVO.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
  • Juniper Ex2200

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex2200 C

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex2200 Vc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex2300

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex2300 C

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex2300m

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex3200

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex3300

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex3300 Vc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex3400

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4200

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4200 Vc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 24p

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 24p S

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 24t

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 24t S

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 32f

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 32f Dc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 32f S

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48mp

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48mp S

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48p

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48p S

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48t

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48tafi

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48t Afi

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48tdc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48t Dc

    HW
    Juniper
    wszystkie wersje
  • Juniper Ex4300 48tdc Afi

    HW
    Juniper
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2026-21902CRITICAL9.3PL ✓ten sam produkt

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2024-21591CRITICAL9.8PL ✓ten sam produkt

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓ten sam produkt

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS