CVE-2021-0221
published 2021-01-15CVE-2021-0221: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP…
medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase abnormally, ultimately leading to a Denial of Service (DoS) in packet processing. The following command could be used to monitor the interface traffic: user@junos> monitor interface traffic Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 6492089274364 (70994959) 6492089235319 (70994956) et-0/0/25 Up 343458103 (1) 156844 (0) ae0 Up 9132519197257 (70994959) 9132519139454 (70994956) This issue affects Juniper Networks Junos OS on QFX Series: all versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S5, 18.4R3-S5; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R1-S5, 19.2R3-S1; 19.3 versions prior to 19.3R2-S5, 19.3R3; 19.4 versions prior to 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S2, 20.2R2.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| juniper_networks | junos_os | >= 17.4 < 17.4R2-S12, 17.4R3-S3 | 17.4R2-S12, 17.4R3-S3 |
| juniper_networks | junos_os | >= 18.1 < 18.1R3-S11 | 18.1R3-S11 |
| juniper_networks | junos_os | >= 18.2 < 18.2R3-S6 | 18.2R3-S6 |
| juniper_networks | junos_os | >= 18.3 < 18.3R3-S4 | 18.3R3-S4 |
| juniper_networks | junos_os | >= 18.4 < 18.4R2-S5, 18.4R3-S5 | 18.4R2-S5, 18.4R3-S5 |
| juniper_networks | junos_os | >= 19.1 < 19.1R1-S6, 19.1R2-S2, 19.1R3-S3 | 19.1R1-S6, 19.1R2-S2, 19.1R3-S3 |
| juniper_networks | junos_os | >= 19.2 < 19.2R1-S5, 19.2R3-S1 | 19.2R1-S5, 19.2R3-S1 |
| juniper_networks | junos_os | >= 19.3 < 19.3R2-S5, 19.3R3 | 19.3R2-S5, 19.3R3 |
| juniper_networks | junos_os | >= 19.4 < 19.4R2-S2, 19.4R3 | 19.4R2-S2, 19.4R3 |
| juniper_networks | junos_os | >= 20.1 < 20.1R2 | 20.1R2 |
| juniper_networks | junos_os | >= 20.2 < 20.2R1-S2, 20.2R2 | 20.2R1-S2, 20.2R2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.1MEDIUM
OSV
tomcat vulnerabilities
osv·2024-07-23·CVSS 6.1
CVE-2019-0221 tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that the Tomcat SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-25329)
GHSA
GHSA-86fx-vw86-g82j: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of sp
ghsa_unreviewed·2022-05-24
CVE-2021-0221 [MEDIUM] CWE-835 GHSA-86fx-vw86-g82j: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of sp
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase abnormally, ultimately leading to a Denial of Service (DoS) in packet processing. The following command could be used to monitor the interface traffic: user@junos> monitor interface traffic Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 6492089274364 (70994959) 6492089235319 (70994956) et-0/0/25 Up 343458103 (1) 156844 (0) ae0 Up 9132519197257 (70994959) 9132519139454 (70994956) This issue affects Juniper Networks Junos OS on QFX Series: all versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) — CVE-2019-0221
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2019-0221 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) — CVE-2019-0221
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) vulnerability
CVE: CVE-2019-0221
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Juniper
CVE-2021-0221: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of sp
vendor_juniper·2021-01-15·CVSS 6.5
CVE-2021-0221 [MEDIUM] CWE-703 CVE-2021-0221: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of sp
CVE-2021-0221: In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loop may occur upon receipt of specific IP multicast traffic. The traffic loop will cause interface traffic to increase abnormally, ultimately leading to a Denial of Service (DoS) in packet processing. The following command could be used to monitor the interface traffic: user@junos> monitor interface traffic Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 6492089274364 (70994959) 6492089235319 (70994956) et-0/0/25 Up 343458103 (1) 156844 (0) ae0 Up 9132519197257 (70994959) 9132519139454 (70994956) This issue affects Juniper Networks Junos OS on QFX Series: all versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-15
Published