CVE-2021-0234Improper Initialization in Networks Junos OS

Severity
5.8MEDIUMNVD
EPSS
0.3%
top 49.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 24

Description

Due to an improper Initialization vulnerability on Juniper Networks Junos OS QFX5100-96S devices with QFX 5e Series image installed, ddos-protection configuration changes will not take effect beyond the default DDoS (Distributed Denial of Service) settings when configured from the CLI. The DDoS protection (jddosd) daemon allows the device to continue to function while protecting the packet forwarding engine (PFE) during the DDoS attack. When this issue occurs, the default DDoS settings within th

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5juniper_networks/junos_os17.317.3R3-S10+9
NVDjuniper/junos10 versions+9

🔴Vulnerability Details

2
GHSA
GHSA-w34x-x7hq-c65h: Due to an improper Initialization vulnerability on Juniper Networks Junos OS QFX5100-96S devices with QFX 5e Series image installed, ddos-protection c2022-05-24
CVEList
Junos OS: QFX5100-96S: DDoS protection does not work as expected.2021-04-22

📋Vendor Advisories

1
Juniper
CVE-2021-0234: Due to an improper Initialization vulnerability on Juniper Networks Junos OS QFX5100-96S devices with QFX 5e Series image installed, ddos-protection c2021-04-22
CVE-2021-0234 — Improper Initialization | cvebase