cbcvebase.
CVE-2021-0254
published 2021-04-22

CVE-2021-0254: A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.57%
83.4th percentile
A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution (RCE). Continued receipt and processing of these packets will sustain the partial DoS. The overlayd daemon handles Overlay OAM packets, such as ping and traceroute, sent to the overlay. The service runs as root by default and listens for UDP connections on port 4789. This issue results from improper buffer size validation, which can lead to a buffer overflow. Unauthenticated attackers can send specially crafted packets to trigger this vulnerability, resulting in possible remote code execution. overlayd runs by default in MX Series, ACX Series, and QFX Series platforms. The SRX Series does not support VXLAN and is therefore not vulnerable to this issue. Other platforms are also vulnerable if a Virtual Extensible LAN (VXLAN) overlay network is configured. This issue affects Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R2-S2, 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R2-S1, 20.2R3; 20.3 versions prior to 20.3R1-S1.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
junipermx_series
juniperqfx_series
junipersrx_series
juniper_networksjunos_os>= 15.1 < 15.1R7-S915.1R7-S9
juniper_networksjunos_os>= 17.3 < 17.3R3-S1117.3R3-S11
juniper_networksjunos_os>= 17.4 < 17.4R2-S13, 17.4R3-S417.4R2-S13, 17.4R3-S4
juniper_networksjunos_os>= 18.1 < 18.1R3-S1218.1R3-S12
juniper_networksjunos_os>= 18.2 < 18.2R2-S8, 18.2R3-S718.2R2-S8, 18.2R3-S7
juniper_networksjunos_os>= 18.3 < 18.3R3-S418.3R3-S4
juniper_networksjunos_os>= 18.4 < 18.4R1-S8, 18.4R2-S7, 18.4R3-S718.4R1-S8, 18.4R2-S7, 18.4R3-S7

Detection & IOCsextracted from sources · hover to see the quote

portUDP/4789
processoverlayd
  • Monitor for unexpected or malformed UDP packets destined to port 4789 (VXLAN) on Junos OS devices, which may indicate exploitation attempts against the overlayd service.
  • Alert on crashes or restarts of the overlayd process, especially when running as root, as this may indicate a buffer overflow exploitation attempt causing a partial DoS.
  • ·The SRX Series is not vulnerable as it does not support VXLAN; exclude SRX devices from detection scope.
  • ·The overlayd service runs as root by default, meaning successful RCE would grant full root-level access on the affected device.
  • ·Vulnerability is exploitable by unauthenticated remote attackers with no prior access required, increasing the attack surface for internet-exposed VXLAN endpoints.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.