Junos OS: QFX10002-60C: Use after free vulnerability found during static code analysis
Published Apr 22, 2021
6.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
Through routine static code analysis of the Juniper Networks Junos OS software codebase, the Secure Development Life Cycle team identified a Use After Free vulnerability in PFE packet processing on the QFX10002-60C switching platform. Exploitation of this vulnerability may allow a logically adjacent attacker to trigger a Denial of Service (DoS). Continued exploitation of this vulnerability will sustain the Denial of Service (DoS) condition. This issue only affects QFX10002-60C devices. No other product or platform is vulnerable to this issue. This issue affects Juniper Networks Junos OS on QFX10002-60C: 19.1 version 19.1R3-S1 and later versions; 19.1 versions prior to 19.1R3-S3; 19.2 version 19.2R2 and later versions; 19.2 versions prior to 19.2R3-S1; 20.2 versions prior to 20.2R1-S2. This issue does not affect Juniper Networks Junos OS: versions prior to 19.1R3; 19.2 versions prior to 19.2R2; any version of 19.3; version 20.2R2 and later releases.
Affected products
-
Affected
- ≥ 19.1R3-S1, < 19.1*
- ≥ 20.2, < 20.2R1-S2
Unaffected
- ≥ 19.2, < 19.2R2
- 19.3
- ≥ 20.2R2, < unspecified
- ≥ unspecified, < 19.1R3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Juniper Networks | Junos OS | unknown | Affected
Unaffected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: Junos OS 19.1R3-S3, 19.2R3-S1, 20.2R1-S2, and all subsequent releases.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2881 Advisory
- https://kb.juniper.net/JSA11153 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2881 | Advisory | |
| https://kb.juniper.net/JSA11153 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data