← Back

CVE-2021-0235

nvd nist
Published: Apr 22, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Exploitability: 1.5 / Impact: 5.3
Source: sirt@juniper.net (Secondary)

Description

On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to incorrect permission scheme assigned to tenant system administrators, a tenant system administrator may inadvertently send their network traffic to one or more tenants while concurrently modifying the overall device system traffic management, affecting all tenants and the service provider. Further, a tenant may inadvertently receive traffic from another tenant. This issue affects: Juniper Networks Junos OS 18.3 version 18.3R1 and later versions on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2; 18.4 version 18.4R1 and later versions on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3; 19.1 versions 19.1R1 and later versions on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3; 19.3 versions prior to 19.3R3-S2 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3; 19.4 versions prior to 19.4R2-S4, 19.4R3-S2 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3; 20.1 versions prior to 20.1R2, 20.1R3 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3 vSRX Series; 20.2 versions prior to 20.2R2-S1, 20.2R3 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3 vSRX Series; 20.3 versions prior to 20.3R1-S2, 20.3R2 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3 vSRX Series; 20.4 versions prior to 20.4R1, 20.4R2 on SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3 vSRX Series. This issue does not affect Juniper Networks Junos OS versions prior to 18.3R1.

Affected (91)

Products: Juniper: Junos
1 product
Junos
Configuration A
91 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 18.3 r1-s1
Version 18.3 r1-s2
Version 18.3 r1-s3
Version 18.3 r1-s4
Version 18.3 r1-s5
Version 18.3 r1-s6
Version 18.3 r1
Version 18.3 r2-s1
Version 18.3 r2-s2
Version 18.3 r2-s3
Version 18.3 r2-s4
Version 18.3 r2
Version 18.3 r3-s1
Version 18.3 r3-s2
Version 18.3 r3-s3
Version 18.3 r3
Version 18.4 r1-s1
Version 18.4 r1-s2
Version 18.4 r1-s3
Version 18.4 r1-s4
Version 18.4 r1-s5
Version 18.4 r1-s6
Version 18.4 r1-s7
Version 18.4 r1
Version 18.4 r2-s1
Version 18.4 r2-s2
Version 18.4 r2-s3
Version 18.4 r2-s4
Version 18.4 r2-s5
Version 18.4 r2-s6
Version 18.4 r2
Version 18.4 r3-s1
Version 18.4 r3-s2
Version 18.4 r3-s3
Version 18.4 r3-s4
Version 18.4 r3-s5
Version 18.4 r3
Version 19.1 r1-s1
Version 19.1 r1-s2
Version 19.1 r1-s3
Version 19.1 r1-s4
Version 19.1 r1-s5
Version 19.1 r1
Version 19.1 r2-s1
Version 19.1 r2
Version 19.1 r3-s1
Version 19.1 r3-s2
Version 19.1 r3-s3
Version 19.1 r3
Version 19.2
Version 19.2 r1-s1
Version 19.2 r1-s2
Version 19.2 r1-s3
Version 19.2 r1-s4
Version 19.2 r1-s5
Version 19.2 r1
Version 19.2 r2-s1
Version 19.2 r2
Version 19.2 r3-s1
Version 19.2 r3
Version 19.3
Version 19.3 r1-s1
Version 19.3 r1
Version 19.3 r2-s1
Version 19.3 r2-s2
Version 19.3 r2-s3
Version 19.3 r2-s4
Version 19.3 r2-s5
Version 19.3 r2
Version 19.3 r3
Version 19.4 r1-s1
Version 19.4 r1-s2
Version 19.4 r1
Version 19.4 r2-s1
Version 19.4 r2-s2
Version 19.4 r2-s3
Version 19.4 r2
Version 19.4 r3-s1
Version 19.4 r3
Version 20.1 r1-s1
Version 20.1 r1-s2
Version 20.1 r1-s3
Version 20.1 r1-s4
Version 20.1 r1
Version 20.2 r1-s1
Version 20.2 r1-s2
Version 20.2 r1-s3
Version 20.2 r1
Version 20.2 r2
Version 20.3 r1-s1
Version 20.3 r1
Running on/withPlatform Versions
Juniper
Srx1500
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx4600
All versions
Juniper
Srx5000
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.