CVE-2021-0203
Last modified
CVE-2021-0203 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop broadcast, multicast, and unknown unicast packets when a specified traffic level is exceeded, thus preventing packets from proliferating and degrading the LAN. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop broadcast, multicast, and unknown unicast packets when a specified traffic level is exceeded, thus preventing packets from proliferating and degrading the LAN. Note: this issue does not affect EX2200, EX3300, EX4200, and EX9200 Series. This issue affects Juniper Networks Junos OS on EX Series and QFX5K Series: 15.1 versions prior to 15.1R7-S7; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R2-S5, 18.4R3-S3; 19.1 versions prior to 19.1R2-S2, 19.1R3-S2; 19.2 versions prior to 19.2R1-S5, 19.2R2-S1, 19.2R3; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2-S1, 19.4R3; 20.1 versions prior to 20.1R1-S2, 20.1R2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 15.1 | — |
| Juniper | Junos | 16.1 | — |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
References
- https://kb.juniper.net/JSA11093Vendor Advisory
- https://kb.juniper.net/JSA11093Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0203?
How severe is CVE-2021-0203?
How do I fix CVE-2021-0203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0196Improper access control in kernel mode driver for some Intel…7.8
- CVE-2021-0197Protection mechanism failure in the firmware for the Intel(R…4.4
- CVE-2021-0198Improper access control in the firmware for the Intel(R) Eth…4.4
- CVE-2021-0199Improper input validation in the firmware for the Intel(R) E…4.4
- CVE-2021-0200Out-of-bounds write in the firmware for Intel(R) Ethernet 70…6.7
- CVE-2021-0202On Juniper Networks MX Series and EX9200 Series platforms wi…7.5
- CVE-2021-0204A sensitive information disclosure vulnerability in delta-ex…7.8
- CVE-2021-0205When the "Intrusion Detection Service" (IDS) feature is conf…5.8
- CVE-2021-0206A NULL Pointer Dereference vulnerability in Juniper Networks…7.5
- CVE-2021-0207An improper interpretation conflict of certain data between …7.5
- CVE-2021-0208An improper input validation vulnerability in the Routing Pr…8.8
- CVE-2021-0209In Juniper Networks Junos OS Evolved an attacker sending cer…6.5
Are you affected by CVE-2021-0203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
