First published: Tue Oct 19 2021(Updated: )
An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Continued receipt and processing of this specific packet will create a sustained Denial of Service (DoS) condition. This issue affects only the following platforms in ACX Series: ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096 devices. Other ACX platforms are not affected from this issue. This issue affects Juniper Networks Junos OS on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096: 18.4 version 18.4R3-S7 and later versions prior to 18.4R3-S8. This issue does not affect: Juniper Networks Junos OS 18.4 versions prior to 18.4R3-S7 on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =18.4-r3-s7 | |
Juniper Acx1000 | ||
Juniper Acx1100 | ||
Juniper Acx2100 | ||
Juniper Acx2200 | ||
Juniper Acx4000 | ||
Juniper Acx500 | ||
Juniper Acx5048 | ||
Juniper Acx5096 |
The following software releases have been updated to resolve this specific issue: Junos OS 18.4R3-S8.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31376 has a severity rating that qualifies it as a Denial of Service vulnerability.
To fix CVE-2021-31376, it is recommended to update your Junos OS to a version that addresses this vulnerability.
CVE-2021-31376 specifically affects Juniper Networks Junos OS version 18.4-r3-s7.
CVE-2021-31376 describes an Improper Input Validation vulnerability that can be exploited to perform Denial of Service attacks.
If CVE-2021-31376 is exploited, it can cause the FXPC service to crash and disrupt network operations.