CVE-2021-0259: Junos OS and Junos OS Evolved: QFX5K Series: Underlay network traffic might not be processed upon receipt of high rate of specific genuine overlay packets in VXLAN scenario
Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the overlay network sends a high volume of specific, legitimate traffic in the overlay network, due to an improperly detected DDoS violation, the leaf might not process certain L2 traffic, sent by spines in the underlay network. Continued receipt and processing of the high volume traffic will sustain the Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on QFX5K Series: 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R2-S8, 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2; 20.3 versions prior to 20.3R1-S2, 20.3R2. Juniper Networks Junos OS Evolved on QFX5220: All versions prior to 20.3R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0259?
CVE-2021-0259 has been classified with a severity rating of high due to its potential to cause instability in the underlay network.
How do I fix CVE-2021-0259?
To address CVE-2021-0259, update affected Junos OS versions to the latest patched release provided by Juniper Networks.
Which versions of Junos OS are affected by CVE-2021-0259?
CVE-2021-0259 affects Junos OS versions 17.3, 17.4, 18.1, 18.2, 18.3, 19.1, 19.2, 19.3, 19.4, and 20.1.
What is the impact of CVE-2021-0259?
The impact of CVE-2021-0259 can lead to instability in the underlay network when the DDoS protection aggregate threshold is exceeded.
Is there a workaround for CVE-2021-0259?
A temporary workaround for CVE-2021-0259 may include monitoring network traffic and adjusting DDoS protection thresholds, though updating is advised.