CWE
670 835
Advisory Published
Updated

CVE-2021-0273: Junos OS and Junos OS Evolved: Trio Chipset: Denial of Service due to packet destined to device's interfaces.

First published: Thu Apr 22 2021(Updated: )

An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960 devices with affected Trio line cards allows an attacker to exploit an interdependency in the PFE UCODE microcode of the Trio chipset with various line cards to cause packets destined to the devices interfaces to cause a Denial of Service (DoS) condition by looping the packet with an unreachable exit condition ('Infinite Loop'). To break this loop once it begins one side of the affected LT interfaces will need to be disabled. Once disabled, the condition will clear and the disabled LT interface can be reenabled. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. This issue only affects LT-LT interfaces. Any other interfaces are not affected by this issue. This issue affects the following cards: MPCE Type 3 3D MPC4E 3D 32XGE MPC4E 3D 2CGE+8XGE EX9200 32x10G SFP EX9200-2C-8XS FPC Type 5-3D FPC Type 5-LSR EX9200 4x40G QSFP An Indicator of Compromise (IoC) can be seen by examining the traffic of the LT-LT interfaces for excessive traffic using the following command: monitor interface traffic Before loop impact: Interface: lt-2/0/0, Enabled, Link is Up Encapsulation: Logical-tunnel, Speed: 100000mbps Traffic statistics: Current delta Input bytes: 3759900268942 (1456 bps) [0] <---------- LT interface utilization is low Output bytes: 3759900344309 (1456 bps) [0] <---------- LT interface utilization is low After loop impact: Interface: lt-2/0/0, Enabled, Link is Up Encapsulation: Logical-tunnel, Speed: 100000mbps Traffic statistics: Current delta Input bytes: 3765160313129 (2158268368 bps) [5260044187] <---------- LT interface utilization is very high Output bytes: 3765160399522 (2158266440 bps) [5260055213] <---------- LT interface utilization is very high This issue affects: Juniper Networks Junos OS on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960. Versions 15.1F6, 16.1R1, and later versions prior to 16.1R7-S8; 17.1 versions prior to 17.1R2-S12; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S10, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S4, 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S1, 19.4R2. This issue does not affect the MX10001. This issue does not affect Juniper Networks Junos OS versions prior to 15.1F6, 16.1R1. Juniper Networks Junos OS Evolved on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960 19.4 versions prior to 19.4R2-EVO. This issue does not affect the MX10001.

Credit: sirt@juniper.net

Affected SoftwareAffected VersionHow to fix
Juniper JUNOS=15.1-f6
Juniper JUNOS=15.1-f6-s1
Juniper JUNOS=15.1-f6-s10
Juniper JUNOS=15.1-f6-s12
Juniper JUNOS=15.1-f6-s2
Juniper JUNOS=15.1-f6-s3
Juniper JUNOS=15.1-f6-s4
Juniper JUNOS=15.1-f6-s5
Juniper JUNOS=15.1-f6-s6
Juniper JUNOS=15.1-f6-s7
Juniper JUNOS=15.1-f6-s8
Juniper JUNOS=15.1-f6-s9
Juniper JUNOS=15.1-f7
Juniper JUNOS=15.1-r
Juniper JUNOS=15.1-r1
Juniper JUNOS=15.1-r2
Juniper JUNOS=15.1-r3
Juniper JUNOS=15.1-r4
Juniper JUNOS=15.1-r4-s7
Juniper JUNOS=15.1-r4-s8
Juniper JUNOS=15.1-r4-s9
Juniper JUNOS=15.1-r5
Juniper JUNOS=15.1-r5-s1
Juniper JUNOS=15.1-r5-s3
Juniper JUNOS=15.1-r5-s5
Juniper JUNOS=15.1-r5-s6
Juniper JUNOS=15.1-r6
Juniper JUNOS=15.1-r6-s1
Juniper JUNOS=15.1-r6-s2
Juniper JUNOS=15.1-r6-s3
Juniper JUNOS=15.1-r6-s4
Juniper JUNOS=15.1-r6-s6
Juniper JUNOS=15.1-r7
Juniper JUNOS=15.1-r7-s1
Juniper JUNOS=15.1-r7-s2
Juniper JUNOS=15.1-r7-s3
Juniper JUNOS=15.1-r7-s4
Juniper JUNOS=15.1-r7-s5
Juniper JUNOS=15.1-r7-s6
Juniper JUNOS=15.1-r7-s7
Juniper JUNOS=15.1-r7-s8
Juniper JUNOS=15.2
Juniper JUNOS=16.1-r1
Juniper JUNOS=16.1-r2
Juniper JUNOS=16.1-r3
Juniper JUNOS=16.1-r3-s10
Juniper JUNOS=16.1-r3-s11
Juniper JUNOS=16.1-r3-s8
Juniper JUNOS=16.1-r4
Juniper JUNOS=16.1-r4-s12
Juniper JUNOS=16.1-r4-s2
Juniper JUNOS=16.1-r4-s3
Juniper JUNOS=16.1-r4-s4
Juniper JUNOS=16.1-r4-s6
Juniper JUNOS=16.1-r4-s8
Juniper JUNOS=16.1-r4-s9
Juniper JUNOS=16.1-r5
Juniper JUNOS=16.1-r5-s4
Juniper JUNOS=16.1-r6
Juniper JUNOS=16.1-r6-s1
Juniper JUNOS=16.1-r6-s3
Juniper JUNOS=16.1-r6-s4
Juniper JUNOS=16.1-r6-s6
Juniper JUNOS=16.1-r7
Juniper JUNOS=16.1-r7-s2
Juniper JUNOS=16.1-r7-s3
Juniper JUNOS=16.1-r7-s4
Juniper JUNOS=16.1-r7-s5
Juniper JUNOS=16.1-r7-s6
Juniper JUNOS=16.1-r7-s7
Juniper JUNOS=17.1
Juniper JUNOS=17.1-r1
Juniper JUNOS=17.1-r1-s7
Juniper JUNOS=17.1-r2
Juniper JUNOS=17.1-r2-s1
Juniper JUNOS=17.1-r2-s10
Juniper JUNOS=17.1-r2-s11
Juniper JUNOS=17.1-r2-s2
Juniper JUNOS=17.1-r2-s3
Juniper JUNOS=17.1-r2-s4
Juniper JUNOS=17.1-r2-s5
Juniper JUNOS=17.1-r2-s6
Juniper JUNOS=17.1-r2-s7
Juniper JUNOS=17.1-r2-s8
Juniper JUNOS=17.1-r2-s9
Juniper JUNOS=17.2
Juniper JUNOS=17.2-r1
Juniper JUNOS=17.2-r1-s1
Juniper JUNOS=17.2-r1-s2
Juniper JUNOS=17.2-r1-s3
Juniper JUNOS=17.2-r1-s4
Juniper JUNOS=17.2-r1-s5
Juniper JUNOS=17.2-r1-s6
Juniper JUNOS=17.2-r1-s7
Juniper JUNOS=17.2-r1-s8
Juniper JUNOS=17.2-r2
Juniper JUNOS=17.2-r2-s11
Juniper JUNOS=17.2-r2-s4
Juniper JUNOS=17.2-r2-s6
Juniper JUNOS=17.2-r2-s7
Juniper JUNOS=17.2-r3
Juniper JUNOS=17.2-r3-s1
Juniper JUNOS=17.2-r3-s2
Juniper JUNOS=17.2-r3-s3
Juniper JUNOS=17.3
Juniper JUNOS=17.3-r1
Juniper JUNOS=17.3-r1-s1
Juniper JUNOS=17.3-r1-s4
Juniper JUNOS=17.3-r2
Juniper JUNOS=17.3-r2-s1
Juniper JUNOS=17.3-r2-s2
Juniper JUNOS=17.3-r2-s3
Juniper JUNOS=17.3-r2-s4
Juniper JUNOS=17.3-r2-s5
Juniper JUNOS=17.3-r3
Juniper JUNOS=17.3-r3
Juniper JUNOS=17.3-r3-s1
Juniper JUNOS=17.3-r3-s10
Juniper JUNOS=17.3-r3-s2
Juniper JUNOS=17.3-r3-s3
Juniper JUNOS=17.3-r3-s4
Juniper JUNOS=17.3-r3-s5
Juniper JUNOS=17.3-r3-s6
Juniper JUNOS=17.3-r3-s7
Juniper JUNOS=17.4
Juniper JUNOS=17.4-r1
Juniper JUNOS=17.4-r1-s1
Juniper JUNOS=17.4-r1-s2
Juniper JUNOS=17.4-r1-s3
Juniper JUNOS=17.4-r1-s4
Juniper JUNOS=17.4-r1-s5
Juniper JUNOS=17.4-r1-s6
Juniper JUNOS=17.4-r1-s7
Juniper JUNOS=17.4-r2
Juniper JUNOS=17.4-r2-s1
Juniper JUNOS=17.4-r2-s2
Juniper JUNOS=17.4-r2-s3
Juniper JUNOS=17.4-r2-s4
Juniper JUNOS=17.4-r2-s5
Juniper JUNOS=17.4-r2-s6
Juniper JUNOS=17.4-r2-s7
Juniper JUNOS=17.4-r2-s8
Juniper JUNOS=17.4-r2-s9
Juniper JUNOS=17.4-r3
Juniper JUNOS=17.4-r3-s1
Juniper JUNOS=18.1
Juniper JUNOS=18.1-r1
Juniper JUNOS=18.1-r2
Juniper JUNOS=18.1-r2-s1
Juniper JUNOS=18.1-r2-s2
Juniper JUNOS=18.1-r2-s4
Juniper JUNOS=18.1-r3
Juniper JUNOS=18.1-r3-s1
Juniper JUNOS=18.1-r3-s2
Juniper JUNOS=18.1-r3-s3
Juniper JUNOS=18.1-r3-s4
Juniper JUNOS=18.1-r3-s5
Juniper JUNOS=18.1-r3-s6
Juniper JUNOS=18.1-r3-s7
Juniper JUNOS=18.1-r3-s8
Juniper JUNOS=18.1-r3-s9
Juniper JUNOS=18.2
Juniper JUNOS=18.2-r1
Juniper JUNOS=18.2-r1
Juniper JUNOS=18.2-r1-s2
Juniper JUNOS=18.2-r1-s3
Juniper JUNOS=18.2-r1-s4
Juniper JUNOS=18.2-r1-s5
Juniper JUNOS=18.2-r2
Juniper JUNOS=18.2-r2-s1
Juniper JUNOS=18.2-r2-s2
Juniper JUNOS=18.2-r2-s3
Juniper JUNOS=18.2-r2-s4
Juniper JUNOS=18.2-r2-s5
Juniper JUNOS=18.2-r2-s6
Juniper JUNOS=18.2-r3
Juniper JUNOS=18.2-r3-s1
Juniper JUNOS=18.2-r3-s2
Juniper JUNOS=18.3
Juniper JUNOS=18.3-r1
Juniper JUNOS=18.3-r1-s1
Juniper JUNOS=18.3-r1-s2
Juniper JUNOS=18.3-r1-s3
Juniper JUNOS=18.3-r1-s4
Juniper JUNOS=18.3-r1-s5
Juniper JUNOS=18.3-r1-s6
Juniper JUNOS=18.3-r2
Juniper JUNOS=18.3-r2-s1
Juniper JUNOS=18.3-r2-s2
Juniper JUNOS=18.3-r2-s3
Juniper JUNOS=18.3-r2-s4
Juniper JUNOS=18.3-r3
Juniper JUNOS=18.3-r3-s1
Juniper JUNOS=18.4
Juniper JUNOS=18.4-r1
Juniper JUNOS=18.4-r1-s1
Juniper JUNOS=18.4-r1-s2
Juniper JUNOS=18.4-r1-s3
Juniper JUNOS=18.4-r1-s4
Juniper JUNOS=18.4-r1-s5
Juniper JUNOS=18.4-r1-s6
Juniper JUNOS=18.4-r2
Juniper JUNOS=18.4-r2-s1
Juniper JUNOS=18.4-r2-s2
Juniper JUNOS=18.4-r2-s3
Juniper JUNOS=18.4-r2-s4
Juniper JUNOS=18.4-r2-s5
Juniper JUNOS=18.4-r2-s6
Juniper JUNOS=18.4-r3
Juniper JUNOS=18.4-r3-s1
Juniper JUNOS=19.1
Juniper JUNOS=19.1-r1
Juniper JUNOS=19.1-r1-s1
Juniper JUNOS=19.1-r1-s2
Juniper JUNOS=19.1-r1-s3
Juniper JUNOS=19.1-r1-s4
Juniper JUNOS=19.1-r2
Juniper JUNOS=19.3
Juniper JUNOS=19.3-r1
Juniper JUNOS=19.3-r1-s1
Juniper JUNOS=19.3-r2
Juniper JUNOS=19.3-r2-s1
Juniper JUNOS=19.3-r2-s2
Juniper JUNOS=19.4-r1
Juniper Junos Os Evolved=19.4-r1
Juniper Junos Os Evolved=19.4-r1-s1
Juniper Acx5800
Juniper Ex9200
Juniper Mx10008
Juniper Mx10016
Juniper Mx240
Juniper Mx480
Juniper Mx960

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 16.1R7-S8, 17.1R2-S12, 17.2R3-S4, 17.3R3-S8, 17.4R2-S10, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S3, 18.3R1-S7, 18.3R3-S2, 18.4R1-S7, 18.4R2-S4, 18.4R3-S2, 19.1R1-S5, 19.1R2-S1, 19.1R3, 19.2R1-S4, 19.2R2, 19.3R2-S3, 19.3R3, 19.4R1-S1, 19.4R2, 20.1R1, and all subsequent releases. Junos OS Evolved: 19.4R2-EVO, 20.1R1-EVO, and all subsequent releases.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203