CVE-2021-31361
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: sirt@juniper.net (Secondary)
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CPU utilization by sending specific IP packets which are being VXLAN encapsulated leading to a partial Denial of Service (DoS). Continued receipted of these specific traffic will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on QFX Series: All versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S3, 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R3; 20.3 versions prior to 20.3R1-S1, 20.3R2. Juniper Networks Junos OS on PTX Series: All versions prior to 18.4R3-S9; 19.1 versions prior to 19.1R3-S6; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R1-S4, 19.4R3-S5; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3-S1; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2.
Affected (216)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 17.3 |
| Running on/with | Platform Versions |
|---|---|
Juniper Qfx10000 | All versions |
Juniper Qfx10002 | All versions |
Juniper Qfx10002 32q | All versions |
Juniper Qfx10002 60c | All versions |
Juniper Qfx10002 72q | All versions |
Juniper Qfx10008 | All versions |
Juniper Qfx10016 | All versions |
Juniper Qfx10k | All versions |
Juniper Qfx3000 G | All versions |
Juniper Qfx3000 M | All versions |
Juniper Qfx3008 I | All versions |
Juniper Qfx3100 | All versions |
Juniper Qfx3500 | All versions |
Juniper Qfx3600 | All versions |
Juniper Qfx3600 I | All versions |
Juniper Qfx5100 | All versions |
Juniper Qfx5100 96s | All versions |
Juniper Qfx5110 | All versions |
Juniper Qfx5120 | All versions |
Juniper Qfx5130 | All versions |
Juniper Qfx5200 | All versions |
Juniper Qfx5200 32c | All versions |
Juniper Qfx5200 48y | All versions |
Juniper Qfx5210 | All versions |
Juniper Qfx5210 64c | All versions |
Juniper Qfx5220 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 18.4 |
| Running on/with | Platform Versions |
|---|---|
Juniper Ptx1000 | All versions |
Juniper Ptx1000 72q | All versions |
Juniper Ptx10000 | All versions |
Juniper Ptx10001 | All versions |
Juniper Ptx10001 36mr | All versions |
Juniper Ptx100016 | All versions |
Juniper Ptx10002 | All versions |
Juniper Ptx10002 60c | All versions |
Juniper Ptx10003 | All versions |
Juniper Ptx10003 160c | All versions |
Juniper Ptx10003 80c | All versions |
Juniper Ptx10003 81cd | All versions |
Juniper Ptx10004 | All versions |
Juniper Ptx10008 | All versions |
Juniper Ptx10016 | All versions |
Juniper Ptx3000 | All versions |
Juniper Ptx5000 | All versions |
Related CWEs
CWE-754
Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
CWE-755
Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
References (2)
Timeline
No history available yet.