CVE-2021-0211: Junos OS and Junos OS Evolved: Upon receipt of a specific BGP FlowSpec message network traffic may be disrupted.
An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3-S1; 19.4 versions prior to 19.4R1-S3, 19.4R2-S3, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S3 20.2R2; 20.3 versions prior to 20.3R1-S1, 20.3R2. Junos OS Evolved: All versions prior to 20.3R1-S1-EVO, 20.3R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0211?
CVE-2021-0211 has been rated as a high-severity vulnerability, posing significant risk to affected systems.
How do I fix CVE-2021-0211?
To fix CVE-2021-0211, update the Juniper Networks Junos OS to the latest patched version that addresses this vulnerability.
What systems are impacted by CVE-2021-0211?
CVE-2021-0211 affects multiple versions of Juniper Networks Junos OS, particularly 17.3, 17.4, and 18.x series.
Can CVE-2021-0211 be exploited remotely?
Yes, CVE-2021-0211 can be exploited remotely by attackers if they send crafted BGP FlowSpec messages.
What are the consequences of CVE-2021-0211 exploitation?
Exploitation of CVE-2021-0211 can lead to unexpected modifications in BGP route advertisements, potentially disrupting network traffic.