CVE-2021-0208: Junos OS and Junos OS Evolved: In bidirectional LSP configurations, on MPLS egress router RPD may core upon receipt of specific malformed RSVP packet.
An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of Service (DoS) condition. Continued receipt of the packet will sustain the Denial of Service. This issue affects: Juniper Networks Junos OS: All versions prior to 17.3R3-S10 except 15.1X49-D240 for SRX series; 17.4 versions prior to 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R3-S2; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R3-S3; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R2-S5, 19.3R3; 19.4 versions prior to 19.4R2-S2, 19.4R3-S1; 20.1 versions prior to 20.1R1-S4, 20.1R2; 15.1X49 versions prior to 15.1X49-D240 on SRX Series. Juniper Networks Junos OS Evolved: 19.3 versions prior to 19.3R2-S5-EVO; 19.4 versions prior to 19.4R2-S2-EVO; 20.1 versions prior to 20.1R1-S4-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0208?
CVE-2021-0208 has been assigned a high severity rating due to its potential to cause a Denial of Service by crashing the Routing Protocol Daemon (RPD).
How do I fix CVE-2021-0208?
To fix CVE-2021-0208, upgrade to a patched version of Junos OS as specified in Juniper's advisories.
What versions of Junos OS are affected by CVE-2021-0208?
CVE-2021-0208 affects specific versions of Junos OS including 15.1x49 and 17.3, among others.
What is the impact of CVE-2021-0208?
The impact of CVE-2021-0208 is a crash of the Routing Protocol Daemon leading to a Denial of Service for bidirectional LSPs.
Is there a workaround for CVE-2021-0208?
A workaround for CVE-2021-0208 may include disabling the RSVP protocol, but upgrading to a secure version is recommended.