cbcvebase.
CVE-2021-31375
published 2021-10-19

CVE-2021-31375: An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may cause RPKI policy-checks to be bypassed. This, in turn, may allow a spoofed advertisement to be accepted or propagated. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S18; 15.1 versions prior to 15.1R7-S9; 17.2 versions prior to 17.2R3-S3; 17.3 versions prior to 17.3R3-S7; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R3-S1; 18.4 versions prior to 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R2; 19.3 versions prior to 19.3R2.

Affected

25 ranges
VendorProductVersion rangeFixed in
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniper_networksjunos_os>= 12.3 < 12.3R12-S1812.3R12-S18
juniper_networksjunos_os>= 15.1 < 15.1R7-S915.1R7-S9
juniper_networksjunos_os>= 17.2 < 17.2R3-S317.2R3-S3
juniper_networksjunos_os>= 17.3 < 17.3R3-S717.3R3-S7
juniper_networksjunos_os>= 17.4 < 17.4R2-S9, 17.4R317.4R2-S9, 17.4R3
juniper_networksjunos_os>= 18.1 < 18.1R3-S1318.1R3-S13
juniper_networksjunos_os>= 18.2 < 18.2R3-S318.2R3-S3
juniper_networksjunos_os>= 18.3 < 18.3R3-S118.3R3-S1
juniper_networksjunos_os>= 18.4 < 18.4R318.4R3
juniper_networksjunos_os>= 19.1 < 19.1R219.1R2
juniper_networksjunos_os>= 19.2 < 19.2R219.2R2
juniper_networksjunos_os>= 19.3 < 19.3R219.3R2