CVE-2021-0240

Description

On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, the Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash if a malformed DHCPv6 packet is received, resulting in a restart of the daemon. The daemon automatically restarts without intervention, but continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects DHCPv6. DHCPv4 is not affected by this issue. This issue affects Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R3-S7; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R3-S2; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.107

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are fixed in junos 17.3R3-S12NCM
Multiple Vulnerabilities are fixed in junos 17.4R3-S5NCM
Multiple Vulnerabilities are fixed in junos 18.1R3-S13NCM
Multiple Vulnerabilities are fixed in junos 18.2R3-S8NCM
Multiple Vulnerabilities are fixed in junos 18.3R3-S5NCM
Multiple Vulnerabilities are fixed in junos 18.4R3-S7NCM
Vulnerabilities CVE-2021-0229,CVE-2021-0240,CVE-2021-0241 are fixed in junos 19.1R3-S5NCM
Multiple Vulnerabilities are fixed in junos 19.2R3-S2NCM
Multiple Vulnerabilities are fixed in junos 19.3R3-S2NCM
Multiple Vulnerabilities are fixed in junos 19.4R3-S2NCM
Multiple Vulnerabilities are fixed in junos 20.1R3NCM
Multiple Vulnerabilities are fixed in junos 20.2R3NCM
Multiple Vulnerabilities are fixed in junos 20.3R2NCM
Multiple Vulnerabilities are fixed in junos 20.4R2.NCM
Improper Check or Handling of Exceptional Conditions Vulnerability (CVE-2021-0240)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234