First published: Thu Apr 22 2021(Updated: )
An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker to cause MQTT server to crash and restart leading to a Denial of Service (DoS) by sending a stream of specific packets. A Juniper Extension Toolkit (JET) application designed with a listening port uses the Message Queue Telemetry Transport (MQTT) protocol to connect to a mosquitto broker that is running on Junos OS to subscribe for events. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS: 16.1R1 and later versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R2-S4, 19.4R3-S2; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R2-S2, 20.2R3; 20.3 versions prior to 20.3R1-S1, 20.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 16.1R1.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | =16.1-r1 | |
Juniper Junos | =16.1-r2 | |
Juniper Junos | =16.1-r3 | |
Juniper Junos | =16.1-r3-s10 | |
Juniper Junos | =16.1-r3-s11 | |
Juniper Junos | =16.1-r3-s8 | |
Juniper Junos | =16.1-r4 | |
Juniper Junos | =16.1-r4-s12 | |
Juniper Junos | =16.1-r4-s2 | |
Juniper Junos | =16.1-r4-s3 | |
Juniper Junos | =16.1-r4-s4 | |
Juniper Junos | =16.1-r4-s6 | |
Juniper Junos | =16.1-r4-s8 | |
Juniper Junos | =16.1-r4-s9 | |
Juniper Junos | =16.1-r5 | |
Juniper Junos | =16.1-r5-s4 | |
Juniper Junos | =16.1-r6 | |
Juniper Junos | =16.1-r6-s1 | |
Juniper Junos | =16.1-r6-s3 | |
Juniper Junos | =16.1-r6-s4 | |
Juniper Junos | =16.1-r6-s6 | |
Juniper Junos | =16.1-r7 | |
Juniper Junos | =16.1-r7-s2 | |
Juniper Junos | =16.1-r7-s3 | |
Juniper Junos | =16.1-r7-s4 | |
Juniper Junos | =16.1-r7-s5 | |
Juniper Junos | =16.1-r7-s6 | |
Juniper Junos | =16.1-r7-s7 | |
Juniper Junos | =16.2 | |
Juniper Junos | =16.2-r1 | |
Juniper Junos | =16.2-r1-s6 | |
Juniper Junos | =16.2-r2 | |
Juniper Junos | =16.2-r2-s1 | |
Juniper Junos | =16.2-r2-s10 | |
Juniper Junos | =16.2-r2-s2 | |
Juniper Junos | =16.2-r2-s5 | |
Juniper Junos | =16.2-r2-s6 | |
Juniper Junos | =16.2-r2-s7 | |
Juniper Junos | =16.2-r2-s8 | |
Juniper Junos | =16.2-r2-s9 | |
Juniper Junos | =16.2-r3 | |
Juniper Junos | =17.1 | |
Juniper Junos | =17.1-r1 | |
Juniper Junos | =17.1-r1-s7 | |
Juniper Junos | =17.1-r2 | |
Juniper Junos | =17.1-r2-s1 | |
Juniper Junos | =17.1-r2-s10 | |
Juniper Junos | =17.1-r2-s11 | |
Juniper Junos | =17.1-r2-s2 | |
Juniper Junos | =17.1-r2-s3 | |
Juniper Junos | =17.1-r2-s4 | |
Juniper Junos | =17.1-r2-s5 | |
Juniper Junos | =17.1-r2-s6 | |
Juniper Junos | =17.1-r2-s7 | |
Juniper Junos | =17.1-r2-s8 | |
Juniper Junos | =17.1-r2-s9 | |
Juniper Junos | =17.1-r3 | |
Juniper Junos | =17.1-r3-s1 | |
Juniper Junos | =17.2 | |
Juniper Junos | =17.2-r1 | |
Juniper Junos | =17.2-r1-s1 | |
Juniper Junos | =17.2-r1-s2 | |
Juniper Junos | =17.2-r1-s3 | |
Juniper Junos | =17.2-r1-s4 | |
Juniper Junos | =17.2-r1-s5 | |
Juniper Junos | =17.2-r1-s6 | |
Juniper Junos | =17.2-r1-s7 | |
Juniper Junos | =17.2-r1-s8 | |
Juniper Junos | =17.2-r2 | |
Juniper Junos | =17.2-r2-s11 | |
Juniper Junos | =17.2-r2-s4 | |
Juniper Junos | =17.2-r2-s6 | |
Juniper Junos | =17.2-r2-s7 | |
Juniper Junos | =17.2-r3 | |
Juniper Junos | =17.2-r3-s1 | |
Juniper Junos | =17.2-r3-s2 | |
Juniper Junos | =17.2-r3-s3 | |
Juniper Junos | =17.3 | |
Juniper Junos | =17.3-r1 | |
Juniper Junos | =17.3-r1-s1 | |
Juniper Junos | =17.3-r1-s4 | |
Juniper Junos | =17.3-r2 | |
Juniper Junos | =17.3-r2-s1 | |
Juniper Junos | =17.3-r2-s2 | |
Juniper Junos | =17.3-r2-s3 | |
Juniper Junos | =17.3-r2-s4 | |
Juniper Junos | =17.3-r2-s5 | |
Juniper Junos | =17.3-r3 | |
Juniper Junos | =17.3-r3 | |
Juniper Junos | =17.3-r3-s1 | |
Juniper Junos | =17.3-r3-s10 | |
Juniper Junos | =17.3-r3-s2 | |
Juniper Junos | =17.3-r3-s3 | |
Juniper Junos | =17.3-r3-s4 | |
Juniper Junos | =17.3-r3-s5 | |
Juniper Junos | =17.3-r3-s6 | |
Juniper Junos | =17.3-r3-s7 | |
Juniper Junos | =17.3-r3-s8 | |
Juniper Junos | =17.3-r3-s9 | |
Juniper Junos | =17.4 | |
Juniper Junos | =17.4-r1 | |
Juniper Junos | =17.4-r1-s1 | |
Juniper Junos | =17.4-r1-s2 | |
Juniper Junos | =17.4-r1-s3 | |
Juniper Junos | =17.4-r1-s4 | |
Juniper Junos | =17.4-r1-s5 | |
Juniper Junos | =17.4-r1-s6 | |
Juniper Junos | =17.4-r1-s7 | |
Juniper Junos | =17.4-r2 | |
Juniper Junos | =17.4-r2-s1 | |
Juniper Junos | =17.4-r2-s10 | |
Juniper Junos | =17.4-r2-s11 | |
Juniper Junos | =17.4-r2-s12 | |
Juniper Junos | =17.4-r2-s2 | |
Juniper Junos | =17.4-r2-s3 | |
Juniper Junos | =17.4-r2-s4 | |
Juniper Junos | =17.4-r2-s5 | |
Juniper Junos | =17.4-r2-s6 | |
Juniper Junos | =17.4-r2-s7 | |
Juniper Junos | =17.4-r2-s8 | |
Juniper Junos | =17.4-r2-s9 | |
Juniper Junos | =17.4-r3 | |
Juniper Junos | =17.4-r3-s1 | |
Juniper Junos | =17.4-r3-s2 | |
Juniper Junos | =17.4-r3-s3 | |
Juniper Junos | =18.1 | |
Juniper Junos | =18.1-r1 | |
Juniper Junos | =18.1-r2 | |
Juniper Junos | =18.1-r2-s1 | |
Juniper Junos | =18.1-r2-s2 | |
Juniper Junos | =18.1-r2-s4 | |
Juniper Junos | =18.1-r3 | |
Juniper Junos | =18.1-r3-s1 | |
Juniper Junos | =18.1-r3-s10 | |
Juniper Junos | =18.1-r3-s11 | |
Juniper Junos | =18.1-r3-s2 | |
Juniper Junos | =18.1-r3-s3 | |
Juniper Junos | =18.1-r3-s4 | |
Juniper Junos | =18.1-r3-s5 | |
Juniper Junos | =18.1-r3-s6 | |
Juniper Junos | =18.1-r3-s7 | |
Juniper Junos | =18.1-r3-s8 | |
Juniper Junos | =18.1-r3-s9 | |
Juniper Junos | =18.2 | |
Juniper Junos | =18.2-r1 | |
Juniper Junos | =18.2-r1 | |
Juniper Junos | =18.2-r1-s2 | |
Juniper Junos | =18.2-r1-s3 | |
Juniper Junos | =18.2-r1-s4 | |
Juniper Junos | =18.2-r1-s5 | |
Juniper Junos | =18.2-r2 | |
Juniper Junos | =18.2-r2-s1 | |
Juniper Junos | =18.2-r2-s2 | |
Juniper Junos | =18.2-r2-s3 | |
Juniper Junos | =18.2-r2-s4 | |
Juniper Junos | =18.2-r2-s5 | |
Juniper Junos | =18.2-r2-s6 | |
Juniper Junos | =18.2-r2-s7 | |
Juniper Junos | =18.2-r3 | |
Juniper Junos | =18.2-r3-s1 | |
Juniper Junos | =18.2-r3-s2 | |
Juniper Junos | =18.2-r3-s3 | |
Juniper Junos | =18.2-r3-s4 | |
Juniper Junos | =18.2-r3-s5 | |
Juniper Junos | =18.2-r3-s6 | |
Juniper Junos | =18.3 | |
Juniper Junos | =18.3-r1 | |
Juniper Junos | =18.3-r1-s1 | |
Juniper Junos | =18.3-r1-s2 | |
Juniper Junos | =18.3-r1-s3 | |
Juniper Junos | =18.3-r1-s4 | |
Juniper Junos | =18.3-r1-s5 | |
Juniper Junos | =18.3-r1-s6 | |
Juniper Junos | =18.3-r2 | |
Juniper Junos | =18.3-r2-s1 | |
Juniper Junos | =18.3-r2-s2 | |
Juniper Junos | =18.3-r2-s3 | |
Juniper Junos | =18.3-r2-s4 | |
Juniper Junos | =18.3-r3 | |
Juniper Junos | =18.3-r3-s1 | |
Juniper Junos | =18.3-r3-s2 | |
Juniper Junos | =18.3-r3-s3 | |
Juniper Junos | =18.4 | |
Juniper Junos | =18.4-r1 | |
Juniper Junos | =18.4-r1-s1 | |
Juniper Junos | =18.4-r1-s2 | |
Juniper Junos | =18.4-r1-s3 | |
Juniper Junos | =18.4-r1-s4 | |
Juniper Junos | =18.4-r1-s5 | |
Juniper Junos | =18.4-r1-s6 | |
Juniper Junos | =18.4-r1-s7 | |
Juniper Junos | =18.4-r2 | |
Juniper Junos | =18.4-r2-s1 | |
Juniper Junos | =18.4-r2-s2 | |
Juniper Junos | =18.4-r2-s3 | |
Juniper Junos | =18.4-r2-s4 | |
Juniper Junos | =18.4-r2-s5 | |
Juniper Junos | =18.4-r2-s6 | |
Juniper Junos | =18.4-r3 | |
Juniper Junos | =18.4-r3-s1 | |
Juniper Junos | =18.4-r3-s2 | |
Juniper Junos | =18.4-r3-s3 | |
Juniper Junos | =18.4-r3-s4 | |
Juniper Junos | =18.4-r3-s5 | |
Juniper Junos | =18.4-r3-s6 | |
Juniper Junos | =19.1 | |
Juniper Junos | =19.1-r1 | |
Juniper Junos | =19.1-r1-s1 | |
Juniper Junos | =19.1-r1-s2 | |
Juniper Junos | =19.1-r1-s3 | |
Juniper Junos | =19.1-r1-s4 | |
Juniper Junos | =19.1-r1-s5 | |
Juniper Junos | =19.1-r2 | |
Juniper Junos | =19.1-r2-s1 | |
Juniper Junos | =19.1-r3 | |
Juniper Junos | =19.1-r3-s1 | |
Juniper Junos | =19.1-r3-s2 | |
Juniper Junos | =19.1-r3-s3 | |
Juniper Junos | =19.1-r3-s4 | |
Juniper Junos | =19.2 | |
Juniper Junos | =19.2-r1 | |
Juniper Junos | =19.2-r1-s1 | |
Juniper Junos | =19.2-r1-s2 | |
Juniper Junos | =19.2-r1-s3 | |
Juniper Junos | =19.2-r1-s4 | |
Juniper Junos | =19.2-r1-s5 | |
Juniper Junos | =19.2-r2 | |
Juniper Junos | =19.2-r2-s1 | |
Juniper Junos | =19.2-r3 | |
Juniper Junos | =19.2-r3-s1 | |
Juniper Junos | =19.3 | |
Juniper Junos | =19.3-r1 | |
Juniper Junos | =19.3-r1-s1 | |
Juniper Junos | =19.3-r2 | |
Juniper Junos | =19.3-r2-s1 | |
Juniper Junos | =19.3-r2-s2 | |
Juniper Junos | =19.3-r2-s3 | |
Juniper Junos | =19.3-r2-s4 | |
Juniper Junos | =19.3-r2-s5 | |
Juniper Junos | =19.3-r3 | |
Juniper Junos | =19.4-r1 | |
Juniper Junos | =19.4-r1-s1 | |
Juniper Junos | =19.4-r1-s2 | |
Juniper Junos | =19.4-r2 | |
Juniper Junos | =19.4-r2-s1 | |
Juniper Junos | =19.4-r2-s2 | |
Juniper Junos | =19.4-r2-s3 | |
Juniper Junos | =19.4-r3 | |
Juniper Junos | =19.4-r3-s1 | |
Juniper Junos | =20.1-r1 | |
Juniper Junos | =20.1-r1-s1 | |
Juniper Junos | =20.1-r1-s2 | |
Juniper Junos | =20.1-r1-s3 | |
Juniper Junos | =20.1-r1-s4 | |
Juniper Junos | =20.2-r1 | |
Juniper Junos | =20.2-r1-s1 | |
Juniper Junos | =20.2-r1-s2 | |
Juniper Junos | =20.2-r2 | |
Juniper Junos | =20.2-r2-s1 | |
Juniper Junos | =20.3-r1 |
The following software releases have been updated to resolve this specific issue: Junos OS: 17.3R3-S11, 17.4R2-S13, 17.4R3-S4, 18.1R3-S12, 18.2R2-S8, 18.2R3-S7, 18.3R3-S4, 18.4R1-S8, 18.4R2-S7, 18.4R3-S7, 19.1R3-S5, 19.2R1-S6, 19.2R3-S2, 19.3R3-S2, 19.4R2-S4, 19.4R3-S2, 20.1R2-S1, 20.1R3, 20.2R2-S2, 20.2R3, 20.3R1-S1, 20.3R2, 20.4R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-0229 is rated as high due to its potential to cause denial of service.
To fix CVE-2021-0229, you should upgrade to the patched version of Juniper's Junos OS where the vulnerability has been resolved.
CVE-2021-0229 affects various Juniper Networks Junos OS versions, specifically versions starting from 16.1-r1 to 20.3-r1.
Exploiting CVE-2021-0229 can lead to an uncontrolled resource consumption, resulting in the MQTT server crashing and restarting, thereby causing a denial of service.
There is no specific workaround for CVE-2021-0229; the recommended action is to apply the available updates from Juniper.