First published: Tue Oct 19 2021(Updated: )
An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as a result of the processing of these packets. Continued receipt and processing of these malformed IPv4 or IPv6 packets will create a sustained Denial of Service (DoS) condition. This issue only affects MPC 7/8/9/10/11 cards, when MAP-E IP reassembly is enabled on these cards. An indicator of compromise is the output: FPC ["FPC ID" # e.g. "0"] PFE #{PFE ID # e.g. "1"] : Fabric Disabled Example: FPC 0 PFE #1 : Fabric Disabled when using the command: show chassis fabric fpcs An example of a healthy result of the command use would be: user@device-re1> show chassis fabric fpcs Fabric management FPC state: FPC 0 PFE #0 Plane 0: Plane enabled Plane 1: Plane enabled Plane 2: Plane enabled Plane 3: Plane enabled Plane 4: Plane enabled Plane 5: Plane enabled Plane 6: Plane enabled Plane 7: Plane enabled This issue affects: Juniper Networks Junos OS on MX Series with MPC 7/8/9/10/11 cards, when MAP-E IP reassembly is enabled on these cards. 17.2 version 17.2R1 and later versions; 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R2-S6, 18.2R3-S3; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R1-S8, 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S5, 19.3R3. This issue does not affect Juniper Networks Junos OS versions prior to 17.2R1.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =17.2-r1 | |
Juniper JUNOS | =17.2-r1-s1 | |
Juniper JUNOS | =17.2-r1-s2 | |
Juniper JUNOS | =17.2-r1-s3 | |
Juniper JUNOS | =17.2-r1-s4 | |
Juniper JUNOS | =17.2-r1-s5 | |
Juniper JUNOS | =17.2-r1-s6 | |
Juniper JUNOS | =17.2-r1-s7 | |
Juniper JUNOS | =17.2-r1-s8 | |
Juniper JUNOS | =17.2-r2 | |
Juniper JUNOS | =17.2-r2-s11 | |
Juniper JUNOS | =17.2-r2-s4 | |
Juniper JUNOS | =17.2-r2-s6 | |
Juniper JUNOS | =17.2-r2-s7 | |
Juniper JUNOS | =17.2-r3 | |
Juniper JUNOS | =17.2-r3-s1 | |
Juniper JUNOS | =17.2-r3-s2 | |
Juniper JUNOS | =17.2-r3-s3 | |
Juniper JUNOS | =17.2-r3-s4 | |
Juniper JUNOS | =17.2x75 | |
Juniper JUNOS | =17.2x75 | |
Juniper JUNOS | =17.2x75-d100 | |
Juniper JUNOS | =17.2x75-d102 | |
Juniper JUNOS | =17.2x75-d110 | |
Juniper JUNOS | =17.2x75-d50 | |
Juniper JUNOS | =17.2x75-d70 | |
Juniper JUNOS | =17.2x75-d90 | |
Juniper JUNOS | =17.2x75-d91 | |
Juniper JUNOS | =17.2x75-d92 | |
Juniper JUNOS | =17.3 | |
Juniper JUNOS | =17.3-r1 | |
Juniper JUNOS | =17.3-r1-s1 | |
Juniper JUNOS | =17.3-r1-s4 | |
Juniper JUNOS | =17.3-r2 | |
Juniper JUNOS | =17.3-r2-s1 | |
Juniper JUNOS | =17.3-r2-s2 | |
Juniper JUNOS | =17.3-r2-s3 | |
Juniper JUNOS | =17.3-r2-s4 | |
Juniper JUNOS | =17.3-r2-s5 | |
Juniper JUNOS | =17.3-r3 | |
Juniper JUNOS | =17.3-r3-s1 | |
Juniper JUNOS | =17.3-r3-s12 | |
Juniper JUNOS | =17.3-r3-s2 | |
Juniper JUNOS | =17.3-r3-s3 | |
Juniper JUNOS | =17.3-r3-s4 | |
Juniper JUNOS | =17.3-r3-s5 | |
Juniper JUNOS | =17.3-r3-s6 | |
Juniper JUNOS | =17.3-r3-s7 | |
Juniper JUNOS | =17.3-r3-s8 | |
Juniper JUNOS | =17.4 | |
Juniper JUNOS | =17.4-r1 | |
Juniper JUNOS | =17.4-r1-s1 | |
Juniper JUNOS | =17.4-r1-s2 | |
Juniper JUNOS | =17.4-r1-s3 | |
Juniper JUNOS | =17.4-r1-s4 | |
Juniper JUNOS | =17.4-r1-s5 | |
Juniper JUNOS | =17.4-r1-s6 | |
Juniper JUNOS | =17.4-r1-s7 | |
Juniper JUNOS | =17.4-r2 | |
Juniper JUNOS | =17.4-r2-s1 | |
Juniper JUNOS | =17.4-r2-s10 | |
Juniper JUNOS | =17.4-r2-s11 | |
Juniper JUNOS | =17.4-r2-s2 | |
Juniper JUNOS | =17.4-r2-s3 | |
Juniper JUNOS | =17.4-r2-s4 | |
Juniper JUNOS | =17.4-r2-s5 | |
Juniper JUNOS | =17.4-r2-s6 | |
Juniper JUNOS | =17.4-r2-s7 | |
Juniper JUNOS | =17.4-r2-s8 | |
Juniper JUNOS | =17.4-r2-s9 | |
Juniper JUNOS | =17.4-r3 | |
Juniper JUNOS | =17.4-r3-s1 | |
Juniper JUNOS | =17.4-r3-s2 | |
Juniper JUNOS | =18.1 | |
Juniper JUNOS | =18.1-r | |
Juniper JUNOS | =18.1-r1 | |
Juniper JUNOS | =18.1-r2 | |
Juniper JUNOS | =18.1-r2-s1 | |
Juniper JUNOS | =18.1-r2-s2 | |
Juniper JUNOS | =18.1-r2-s4 | |
Juniper JUNOS | =18.1-r3 | |
Juniper JUNOS | =18.1-r3-s1 | |
Juniper JUNOS | =18.1-r3-s10 | |
Juniper JUNOS | =18.1-r3-s2 | |
Juniper JUNOS | =18.1-r3-s3 | |
Juniper JUNOS | =18.1-r3-s4 | |
Juniper JUNOS | =18.1-r3-s5 | |
Juniper JUNOS | =18.1-r3-s6 | |
Juniper JUNOS | =18.1-r3-s7 | |
Juniper JUNOS | =18.1-r3-s8 | |
Juniper JUNOS | =18.1-r3-s9 | |
Juniper JUNOS | =18.2 | |
Juniper JUNOS | =18.2-r | |
Juniper JUNOS | =18.2-r1 | |
Juniper JUNOS | =18.2-r1 | |
Juniper JUNOS | =18.2-r1-s2 | |
Juniper JUNOS | =18.2-r1-s3 | |
Juniper JUNOS | =18.2-r1-s4 | |
Juniper JUNOS | =18.2-r1-s5 | |
Juniper JUNOS | =18.2-r2 | |
Juniper JUNOS | =18.2-r2-s1 | |
Juniper JUNOS | =18.2-r2-s2 | |
Juniper JUNOS | =18.2-r2-s3 | |
Juniper JUNOS | =18.2-r2-s4 | |
Juniper JUNOS | =18.2-r2-s5 | |
Juniper JUNOS | =18.2-r3 | |
Juniper JUNOS | =18.2-r3-s1 | |
Juniper JUNOS | =18.2-r3-s2 | |
Juniper JUNOS | =18.3 | |
Juniper JUNOS | =18.3-r | |
Juniper JUNOS | =18.3-r1 | |
Juniper JUNOS | =18.3-r1-s1 | |
Juniper JUNOS | =18.3-r1-s2 | |
Juniper JUNOS | =18.3-r1-s3 | |
Juniper JUNOS | =18.3-r1-s4 | |
Juniper JUNOS | =18.3-r1-s5 | |
Juniper JUNOS | =18.3-r1-s6 | |
Juniper JUNOS | =18.3-r2 | |
Juniper JUNOS | =18.3-r2-s1 | |
Juniper JUNOS | =18.3-r2-s2 | |
Juniper JUNOS | =18.3-r2-s3 | |
Juniper JUNOS | =18.3-r3 | |
Juniper JUNOS | =18.4 | |
Juniper JUNOS | =18.4-r1 | |
Juniper JUNOS | =18.4-r1-s1 | |
Juniper JUNOS | =18.4-r1-s2 | |
Juniper JUNOS | =18.4-r1-s3 | |
Juniper JUNOS | =18.4-r1-s4 | |
Juniper JUNOS | =18.4-r1-s5 | |
Juniper JUNOS | =18.4-r1-s6 | |
Juniper JUNOS | =18.4-r1-s7 | |
Juniper JUNOS | =18.4-r2 | |
Juniper JUNOS | =18.4-r2-s1 | |
Juniper JUNOS | =18.4-r2-s2 | |
Juniper JUNOS | =18.4-r2-s3 | |
Juniper JUNOS | =18.4-r2-s4 | |
Juniper JUNOS | =19.1 | |
Juniper JUNOS | =19.1-r1 | |
Juniper JUNOS | =19.1-r1-s1 | |
Juniper JUNOS | =19.1-r1-s2 | |
Juniper JUNOS | =19.1-r1-s3 | |
Juniper JUNOS | =19.1-r1-s4 | |
Juniper JUNOS | =19.1-r1-s5 | |
Juniper JUNOS | =19.1-r2 | |
Juniper JUNOS | =19.1-r2-s1 | |
Juniper JUNOS | =19.2 | |
Juniper JUNOS | =19.2-r1 | |
Juniper JUNOS | =19.2-r1-s1 | |
Juniper JUNOS | =19.2-r1-s2 | |
Juniper JUNOS | =19.2-r1-s3 | |
Juniper JUNOS | =19.2-r1-s4 | |
Juniper JUNOS | =19.3 | |
Juniper JUNOS | =19.3-r1 | |
Juniper JUNOS | =19.3-r1-s1 | |
Juniper JUNOS | =19.3-r2 | |
Juniper JUNOS | =19.3-r2-s1 | |
Juniper JUNOS | =19.3-r2-s2 | |
Juniper JUNOS | =19.3-r2-s3 | |
Juniper JUNOS | =19.3-r2-s4 | |
Juniper Mx10 | ||
Juniper Mx10000 | ||
Juniper Mx10003 | ||
Juniper Mx10008 | ||
Juniper Mx10016 | ||
Juniper Mx104 | ||
Juniper Mx150 | ||
Juniper Mx2008 | ||
Juniper Mx2010 | ||
Juniper Mx2020 | ||
Juniper Mx204 | ||
Juniper Mx240 | ||
Juniper Mx40 | ||
Juniper Mx480 | ||
Juniper Mx5 | ||
Juniper Mx80 | ||
Juniper Mx960 |
The following software releases have been updated to resolve this specific issue: 17.3R3-S9, 17.4R2-S12, 17.4R3-S3, 18.1R3-S11, 18.2R2-S6, 18.2R3-S3, 18.3R2-S4, 18.3R3-S1, 18.4R1-S8, 18.4R2-S5, 18.4R3, 19.1R1-S6, 19.1R2-S2, 19.1R3, 19.2R1-S5, 19.2R2, 19.3R2-S5, 19.3R3, 19.4R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.