CVE-2021-0230
Last modified
CVE-2021-0230 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is consumed, the traffic will be impacted and a reboot might be required. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is consumed, the traffic will be impacted and a reboot might be required. The following log can be seen if this issue happens. /kernel: rt_pfe_veto: Memory over consumed. Op 1 err 12, rtsm_id 0:-1, msg type 72 /kernel: rt_pfe_veto: free kmem_map memory = (20770816) curproc = kmd An administrator can use the following CLI command to monitor the status of memory consumption (ifstat bucket): user@device > show system virtual-memory no-forwarding | match ifstat Type InUse MemUse HighUse Limit Requests Limit Limit Size(s) ifstat 2588977 162708K - 19633958 <<<< user@device > show system virtual-memory no-forwarding | match ifstat Type InUse MemUse HighUse Limit Requests Limit Limit Size(s) ifstat 3021629 189749K - 22914415 <<<< This issue affects Juniper Networks Junos OS on SRX Series: 17.1 versions 17.1R3 and above prior to 17.3R3-S11; 17.4 versions prior to 17.4R3-S5; 18.2 versions prior to 18.2R3-S7, 18.2R3-S8; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S7, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2-S2, 20.2R3; 20.3 versions prior to 20.3R1-S2, 20.3R2. This issue does not affect Juniper Networks Junos OS prior to 17.1R3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 17.1 | R3 |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
| Juniper | Junos | 20.2 | R1 |
| Juniper | Junos | 20.3 | R1 |
References
- https://kb.juniper.net/JSA11125Vendor Advisory
- https://kb.juniper.net/JSA11125Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0230?
How severe is CVE-2021-0230?
How do I fix CVE-2021-0230?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0224A vulnerability in the handling of internal resources necess…6.5
- CVE-2021-0225An Improper Check for Unusual or Exceptional Conditions in J…5.8
- CVE-2021-0226On Juniper Networks Junos OS Evolved devices, receipt of a s…7.5
- CVE-2021-0227An improper restriction of operations within the bounds of a…7.5
- CVE-2021-0228An improper check for unusual or exceptional conditions vuln…6.5
- CVE-2021-0229An uncontrolled resource consumption vulnerability in Messag…5.3
- CVE-2021-0231A path traversal vulnerability in the Juniper Networks SRX a…6.5
- CVE-2021-0232An authentication bypass vulnerability in the Juniper Networ…7.4
- CVE-2021-0233A vulnerability in Juniper Networks Junos OS ACX500 Series, …7.5
- CVE-2021-0234Due to an improper Initialization vulnerability on Juniper N…5.8
- CVE-2021-0235On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with S…7.3
- CVE-2021-0236Due to an improper check for unusual or exceptional conditio…6.5
Are you affected by CVE-2021-0230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
