CVE-2021-0281: Junos OS and Junos OS Evolved: Specific packets can trigger rpd crash when BGP Origin Validation is configured with RPKI
On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server may cause routing process daemon (RPD) to crash and restart, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8, 18.4R3-S8; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R2-S4, 19.4R3-S3; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2. Juniper Networks Junos OS Evolved All versions prior to 20.4R2-S2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0281?
CVE-2021-0281 is considered a high severity vulnerability as it may lead to a Denial of Service (DoS) condition.
How do I fix CVE-2021-0281?
To fix CVE-2021-0281, update your affected Juniper Networks Junos OS device to a version that addresses this vulnerability.
Which versions of Junos OS are affected by CVE-2021-0281?
CVE-2021-0281 affects multiple versions of Junos OS, including 17.3, 17.4, and certain 18.x and 19.x versions.
What is the impact of CVE-2021-0281?
The impact of CVE-2021-0281 is the potential crashing and restarting of the routing process daemon (RPD), causing DoS.
Can CVE-2021-0281 be exploited remotely?
Yes, CVE-2021-0281 can be exploited remotely if the vulnerable device is accessible from the internet.