First published: Wed Apr 14 2021(Updated: )
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, the Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash if a malformed DHCPv6 packet is received, resulting in a restart of the daemon. The daemon automatically restarts without intervention, but continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects DHCPv6. DHCPv4 is not affected by this issue. This issue affects Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R3-S7; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R3-S2; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | =17.3 | |
Juniper Junos | =17.3-r1 | |
Juniper Junos | =17.3-r1-s1 | |
Juniper Junos | =17.3-r1-s4 | |
Juniper Junos | =17.3-r2 | |
Juniper Junos | =17.3-r2-s1 | |
Juniper Junos | =17.3-r2-s2 | |
Juniper Junos | =17.3-r2-s3 | |
Juniper Junos | =17.3-r2-s4 | |
Juniper Junos | =17.3-r2-s5 | |
Juniper Junos | =17.3-r3 | |
Juniper Junos | =17.3-r3 | |
Juniper Junos | =17.3-r3-s1 | |
Juniper Junos | =17.3-r3-s10 | |
Juniper Junos | =17.3-r3-s11 | |
Juniper Junos | =17.3-r3-s2 | |
Juniper Junos | =17.3-r3-s3 | |
Juniper Junos | =17.3-r3-s4 | |
Juniper Junos | =17.3-r3-s5 | |
Juniper Junos | =17.3-r3-s6 | |
Juniper Junos | =17.3-r3-s7 | |
Juniper Junos | =17.3-r3-s8 | |
Juniper Junos | =17.3-r3-s9 | |
Juniper Junos | =17.4 | |
Juniper Junos | =17.4-r1 | |
Juniper Junos | =17.4-r1-s1 | |
Juniper Junos | =17.4-r1-s2 | |
Juniper Junos | =17.4-r1-s3 | |
Juniper Junos | =17.4-r1-s4 | |
Juniper Junos | =17.4-r1-s5 | |
Juniper Junos | =17.4-r1-s6 | |
Juniper Junos | =17.4-r1-s7 | |
Juniper Junos | =17.4-r2 | |
Juniper Junos | =17.4-r2-s1 | |
Juniper Junos | =17.4-r2-s10 | |
Juniper Junos | =17.4-r2-s11 | |
Juniper Junos | =17.4-r2-s2 | |
Juniper Junos | =17.4-r2-s3 | |
Juniper Junos | =17.4-r2-s4 | |
Juniper Junos | =17.4-r2-s5 | |
Juniper Junos | =17.4-r2-s6 | |
Juniper Junos | =17.4-r2-s7 | |
Juniper Junos | =17.4-r2-s8 | |
Juniper Junos | =17.4-r2-s9 | |
Juniper Junos | =17.4-r3 | |
Juniper Junos | =17.4-r3-s1 | |
Juniper Junos | =17.4-r3-s2 | |
Juniper Junos | =17.4-r3-s3 | |
Juniper Junos | =17.4-r3-s4 | |
Juniper Junos | =18.1 | |
Juniper Junos | =18.1-r1 | |
Juniper Junos | =18.1-r2 | |
Juniper Junos | =18.1-r2-s1 | |
Juniper Junos | =18.1-r2-s2 | |
Juniper Junos | =18.1-r2-s4 | |
Juniper Junos | =18.1-r3 | |
Juniper Junos | =18.1-r3-s1 | |
Juniper Junos | =18.1-r3-s10 | |
Juniper Junos | =18.1-r3-s11 | |
Juniper Junos | =18.1-r3-s12 | |
Juniper Junos | =18.1-r3-s2 | |
Juniper Junos | =18.1-r3-s3 | |
Juniper Junos | =18.1-r3-s4 | |
Juniper Junos | =18.1-r3-s5 | |
Juniper Junos | =18.1-r3-s6 | |
Juniper Junos | =18.1-r3-s7 | |
Juniper Junos | =18.1-r3-s8 | |
Juniper Junos | =18.1-r3-s9 | |
Juniper Junos | =18.2 | |
Juniper Junos | =18.2-r1 | |
Juniper Junos | =18.2-r1 | |
Juniper Junos | =18.2-r1-s2 | |
Juniper Junos | =18.2-r1-s3 | |
Juniper Junos | =18.2-r1-s4 | |
Juniper Junos | =18.2-r1-s5 | |
Juniper Junos | =18.2-r2 | |
Juniper Junos | =18.2-r2-s1 | |
Juniper Junos | =18.2-r2-s2 | |
Juniper Junos | =18.2-r2-s3 | |
Juniper Junos | =18.2-r2-s4 | |
Juniper Junos | =18.2-r2-s5 | |
Juniper Junos | =18.2-r2-s6 | |
Juniper Junos | =18.2-r2-s7 | |
Juniper Junos | =18.2-r3 | |
Juniper Junos | =18.2-r3-s1 | |
Juniper Junos | =18.2-r3-s2 | |
Juniper Junos | =18.2-r3-s3 | |
Juniper Junos | =18.2-r3-s4 | |
Juniper Junos | =18.2-r3-s5 | |
Juniper Junos | =18.2-r3-s6 | |
Juniper Junos | =18.2-r3-s7 | |
Juniper Junos | =18.3 | |
Juniper Junos | =18.3-r1 | |
Juniper Junos | =18.3-r1-s1 | |
Juniper Junos | =18.3-r1-s2 | |
Juniper Junos | =18.3-r1-s3 | |
Juniper Junos | =18.3-r1-s4 | |
Juniper Junos | =18.3-r1-s5 | |
Juniper Junos | =18.3-r1-s6 | |
Juniper Junos | =18.3-r2 | |
Juniper Junos | =18.3-r2-s1 | |
Juniper Junos | =18.3-r2-s2 | |
Juniper Junos | =18.3-r2-s3 | |
Juniper Junos | =18.3-r2-s4 | |
Juniper Junos | =18.3-r3 | |
Juniper Junos | =18.3-r3-s1 | |
Juniper Junos | =18.3-r3-s2 | |
Juniper Junos | =18.3-r3-s3 | |
Juniper Junos | =18.3-r3-s4 | |
Juniper Junos | =18.4 | |
Juniper Junos | =18.4-r1 | |
Juniper Junos | =18.4-r1-s1 | |
Juniper Junos | =18.4-r1-s2 | |
Juniper Junos | =18.4-r1-s3 | |
Juniper Junos | =18.4-r1-s4 | |
Juniper Junos | =18.4-r1-s5 | |
Juniper Junos | =18.4-r1-s6 | |
Juniper Junos | =18.4-r1-s7 | |
Juniper Junos | =18.4-r2 | |
Juniper Junos | =18.4-r2-s1 | |
Juniper Junos | =18.4-r2-s2 | |
Juniper Junos | =18.4-r2-s3 | |
Juniper Junos | =18.4-r2-s4 | |
Juniper Junos | =18.4-r2-s5 | |
Juniper Junos | =18.4-r2-s6 | |
Juniper Junos | =18.4-r3 | |
Juniper Junos | =18.4-r3-s1 | |
Juniper Junos | =18.4-r3-s2 | |
Juniper Junos | =18.4-r3-s3 | |
Juniper Junos | =18.4-r3-s4 | |
Juniper Junos | =18.4-r3-s5 | |
Juniper Junos | =18.4-r3-s6 | |
Juniper Junos | =19.1 | |
Juniper Junos | =19.1-r1 | |
Juniper Junos | =19.1-r1-s1 | |
Juniper Junos | =19.1-r1-s2 | |
Juniper Junos | =19.1-r1-s3 | |
Juniper Junos | =19.1-r1-s4 | |
Juniper Junos | =19.1-r1-s5 | |
Juniper Junos | =19.1-r2 | |
Juniper Junos | =19.1-r2-s1 | |
Juniper Junos | =19.1-r3 | |
Juniper Junos | =19.1-r3-s1 | |
Juniper Junos | =19.1-r3-s2 | |
Juniper Junos | =19.1-r3-s3 | |
Juniper Junos | =19.1-r3-s4 | |
Juniper Junos | =19.2 | |
Juniper Junos | =19.2-r1 | |
Juniper Junos | =19.2-r1-s1 | |
Juniper Junos | =19.2-r1-s2 | |
Juniper Junos | =19.2-r1-s3 | |
Juniper Junos | =19.2-r1-s4 | |
Juniper Junos | =19.2-r1-s5 | |
Juniper Junos | =19.2-r2 | |
Juniper Junos | =19.2-r2-s1 | |
Juniper Junos | =19.2-r3 | |
Juniper Junos | =19.2-r3-s1 | |
Juniper Junos | =19.3 | |
Juniper Junos | =19.3-r1 | |
Juniper Junos | =19.3-r1-s1 | |
Juniper Junos | =19.3-r2 | |
Juniper Junos | =19.3-r2-s1 | |
Juniper Junos | =19.3-r2-s2 | |
Juniper Junos | =19.3-r2-s3 | |
Juniper Junos | =19.3-r2-s4 | |
Juniper Junos | =19.3-r2-s5 | |
Juniper Junos | =19.3-r3 | |
Juniper Junos | =19.4-r1 | |
Juniper Junos | =19.4-r1-s1 | |
Juniper Junos | =19.4-r1-s2 | |
Juniper Junos | =19.4-r2 | |
Juniper Junos | =19.4-r2-s1 | |
Juniper Junos | =19.4-r2-s2 | |
Juniper Junos | =19.4-r3 | |
Juniper Junos | =19.4-r3-s1 | |
Juniper Junos | =20.1-r1 | |
Juniper Junos | =20.1-r1-s1 | |
Juniper Junos | =20.1-r1-s2 | |
Juniper Junos | =20.1-r1-s3 | |
Juniper Junos | =20.1-r1-s4 | |
Juniper Junos | =20.1-r2 | |
Juniper Junos | =20.2-r1 | |
Juniper Junos | =20.2-r1-s1 | |
Juniper Junos | =20.2-r1-s2 | |
Juniper Junos | =20.2-r1-s3 | |
Juniper Junos | =20.2-r2 | |
Juniper Junos | =20.2-r2-s1 | |
Juniper Junos | =20.2-r2-s2 | |
Juniper Junos | =20.3-r1 | |
Juniper Junos | =20.3-r1-s1 | |
Juniper Junos | =20.4-r1 | |
Juniper Junos | =20.4-r1-s1 |
The following software releases have been updated to resolve this specific issue: Junos OS 17.3R3-S12, 17.4R3-S5, 18.1R3-S13, 18.2R3-S8, 18.3R3-S5, 18.4R1-S8, 18.4R3-S7, 19.1R3-S5, 19.2R3-S2, 19.3R3-S2, 19.4R3-S2, 20.1R3, 20.2R2-S3, 20.2R3, 20.3R2, 20.4R2, 21.1R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-0240 is classified as a high severity vulnerability due to the potential impact of service disruption.
To fix CVE-2021-0240, update your Junos OS to version 17.4 or later to ensure the DHCP daemon is not vulnerable to crafted packets.
CVE-2021-0240 affects Juniper Networks Junos OS versions 17.3, 17.4, 18.1, 18.2, 18.3, 18.4, and 19.1 before the appropriate patches are applied.
If exploited, CVE-2021-0240 can cause the Dynamic Host Configuration Protocol Daemon (JDHCPD) to crash, leading to loss of DHCP services.
Currently, the best course of action is to apply the latest updates to Junos OS as there are no formal workarounds provided for CVE-2021-0240.