CVE-2021-0206: Junos OS: NFX Series, SRX Series: PFE may crash upon receipt of specific packet when SSL Proxy is configured.
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS). By continuously sending these specific packets, an attacker can repeatedly disable the PFE causing a sustained Denial of Service (DoS). This issue only affects Juniper Networks NFX Series, SRX Series platforms when SSL Proxy is configured. This issue affects Juniper Networks Junos OS on NFX Series and SRX Series: 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R3-S1; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS versions on NFX Series and SRX Series prior to 18.3R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-0206?
CVE-2021-0206 is a NULL Pointer Dereference vulnerability in Juniper Networks Junos OS that allows an attacker to send a specific packet causing the packet forwarding engine (PFE) to crash and restart, resulting in a Denial of Service (DoS).
Which Juniper Networks Junos OS versions are affected by CVE-2021-0206?
Juniper Networks Junos OS versions 18.3 to 19.3 are affected by CVE-2021-0206.
What is the severity of CVE-2021-0206?
CVE-2021-0206 has a severity rating of 7.5 (High).
How can I fix CVE-2021-0206?
To fix CVE-2021-0206, it is recommended to upgrade Juniper Networks Junos OS to a non-vulnerable version as mentioned in the Juniper advisory.
Where can I find more information about CVE-2021-0206?
You can find more information about CVE-2021-0206 in the Juniper Networks security advisory: https://kb.juniper.net/JSA11096