CVE-2021-0277: Junos OS and Junos OS Evolved: LLDP Out-of-Bounds Read vulnerability in l2cpd
An Out-of-bounds Read vulnerability in the processing of specially crafted LLDP frames by the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved may allow an attacker to cause a Denial of Service (DoS), or may lead to remote code execution (RCE). Continued receipt and processing of these frames, sent from the local broadcast domain, will repeatedly crash the l2cpd process and sustain the Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S18; 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8, 18.4R3-S8; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S3; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3-S1; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2. Juniper Networks Junos OS Evolved versions prior to 20.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0277?
CVE-2021-0277 is considered a critical vulnerability due to the potential for denial of service and remote code execution.
How do I fix CVE-2021-0277?
To fix CVE-2021-0277, it's recommended to upgrade to the latest patched version of Junos OS provided by Juniper Networks.
What versions of Junos OS are affected by CVE-2021-0277?
CVE-2021-0277 affects multiple versions of Junos OS, including versions 12.3, 15.1, 17.3, 17.4, and 18.1 through 20.4.
What type of attack does CVE-2021-0277 enable?
CVE-2021-0277 enables attackers to conduct denial of service attacks or potentially execute remote code on affected devices.
Is there a workaround for CVE-2021-0277?
There are no known workarounds for CVE-2021-0277, making the upgrade to a patched version the only effective solution.