CVE-2021-0241
Last modified
CVE-2021-0241 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash with a core dump if a specific DHCPv6 packet is received, resulting in a restart of the daemon. The daemon automatically restarts without intervention, but continued receipt and processing of these specific packets will repeatedly crash the JDHCPD process and sustain the Denial of Service (DoS) condition. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash with a core dump if a specific DHCPv6 packet is received, resulting in a restart of the daemon. The daemon automatically restarts without intervention, but continued receipt and processing of these specific packets will repeatedly crash the JDHCPD process and sustain the Denial of Service (DoS) condition. This issue only affects DHCPv6. DHCPv4 is not affected by this issue. This issue affects: Juniper Networks Junos OS 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R3-S7; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior to 19.3R3-S1, 19.3R3-S2; 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R3; 20.3 versions prior to 20.3R1-S2, 20.3R2.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
| Juniper | Junos | 20.2 | R1 |
| Juniper | Junos | 20.3 | R1 |
| Juniper | Junos | 20.4 | R1 |
References
- https://kb.juniper.net/JSA11168Vendor Advisory
- https://kb.juniper.net/JSA11168Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0241?
How severe is CVE-2021-0241?
How do I fix CVE-2021-0241?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0235On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with S…7.3
- CVE-2021-0236Due to an improper check for unusual or exceptional conditio…6.5
- CVE-2021-0237On Juniper Networks EX4300-MP Series, EX4600 Series, EX4650 …6.5
- CVE-2021-0238When a MX Series is configured as a Broadband Network Gatewa…5.5
- CVE-2021-0239In Juniper Networks Junos OS Evolved, receipt of a stream of…6.5
- CVE-2021-0240On Juniper Networks Junos OS platforms configured as DHCPv6 …6.5
- CVE-2021-0242A vulnerability due to the improper handling of direct memor…6.5
- CVE-2021-0243Improper Handling of Unexpected Data in the firewall policer…4.7
- CVE-2021-0244A signal handler race condition exists in the Layer 2 Addres…7.4
- CVE-2021-0245A Use of Hard-coded Credentials vulnerability in Juniper Net…7.8
- CVE-2021-0246On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with S…7.3
- CVE-2021-0247A Race Condition (Concurrent Execution using Shared Resource…5.5
Are you affected by CVE-2021-0241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
