CVE-2021-0221

Description

In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase abnormally, ultimately leading to a Denial of Service (DoS) in packet processing. The following command could be used to monitor the interface traffic: user@junos> monitor interface traffic Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 6492089274364 (70994959) 6492089235319 (70994956) et-0/0/25 Up 343458103 (1) 156844 (0) ae0 Up 9132519197257 (70994959) 9132519139454 (70994956) This issue affects Juniper Networks Junos OS on QFX Series: all versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S5, 18.4R3-S5; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R1-S5, 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3; 19.4 versions prior to 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S2, 20.2R2.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.081

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are fixed in junos 17.3R3-S10NCM
Multiple Vulnerabilities are fixed in junos 17.4R3-S3NCM
Multiple Vulnerabilities are fixed in junos 18.1R3-S11NCM
Multiple Vulnerabilities are fixed in junos 18.2R3-S6NCM
Multiple Vulnerabilities are fixed in junos 18.3R3-S4NCM
Vulnerabilities CVE-2020-1664,CVE-2021-0210,CVE-2021-0221 are fixed in junos 18.4R3-S5NCM
Multiple Vulnerabilities are fixed in junos 19.1R3-S3NCM
Multiple Vulnerabilities are fixed in junos 19.2R3-S1NCM
Multiple Vulnerabilities are fixed in junos 19.3R3NCM
Multiple Vulnerabilities are fixed in junos 19.4R3NCM
Multiple Vulnerabilities are fixed in junos 20.1R2NCM
Multiple Vulnerabilities are fixed in junos 20.2R2.NCM
Improper Check or Handling of Exceptional Conditions Vulnerability (CVE-2021-0221)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234