CVE-2021-0258Race Condition in Networks Junos OS

CWE-362Race Condition4 documents4 sources
Severity
5.9MEDIUMNVD
EPSS
0.2%
top 57.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 24

Description

A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these transit packets will create a sustained Denial of Service (DoS) condition. This issue only occurs when TCPv6 packets are routed through the management interface. Other transit traffic, and traffic destined to the management interface, are u

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5juniper_networks/junos_os17.317.3R3-S9+9
NVDjuniper/junos11 versions+10

🔴Vulnerability Details

2
GHSA
GHSA-9pw6-g5gg-555m: A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attack2022-05-24
CVEList
Junos OS: Kernel panic upon receipt of specific TCPv6 packet on management interface2021-04-22

📋Vendor Advisories

1
Juniper
CVE-2021-0258: A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attack2021-04-22
CVE-2021-0258 — Race Condition in Networks Junos OS | cvebase