CVE-2021-0249
Last modified
CVE-2021-0249 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS may allow an attacker to arbitrarily execute code or commands on the target to take over or otherwise impact the device by sending crafted packets to or through the device. This issue affects: Juniper Networks Junos OS on SRX Series: 15.1X49 versions prior to 15.1X49-D190; 17.4 versions prior to 17.4R2-S9; 17.4R3 and later versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S1; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S4, 19.1R2; 19.2 versions prior to 19.2R1-S1, 19.2R2. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS may allow an attacker to arbitrarily execute code or commands on the target to take over or otherwise impact the device by sending crafted packets to or through the device. This issue affects: Juniper Networks Junos OS on SRX Series: 15.1X49 versions prior to 15.1X49-D190; 17.4 versions prior to 17.4R2-S9; 17.4R3 and later versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S1; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S4, 19.1R2; 19.2 versions prior to 19.2R1-S1, 19.2R2. An indicator of compromise can be the following text in the UTM log: RT_UTM: AV_FILE_NOT_SCANNED_PASSED_MT:
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 15.1x49 |
| Juniper | Junos | 17.4 |
| Juniper | Junos | 18.1 |
| Juniper | Junos | 18.2 |
| Juniper | Junos | 18.3 |
| Juniper | Junos | 18.4 |
| Juniper | Junos | 19.1 |
| Juniper | Junos | 19.2 |
References
- https://kb.juniper.net/JSA11142Vendor Advisory
- https://kb.juniper.net/JSA11142Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0249?
How severe is CVE-2021-0249?
How do I fix CVE-2021-0249?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0243Improper Handling of Unexpected Data in the firewall policer…4.7
- CVE-2021-0244A signal handler race condition exists in the Layer 2 Addres…7.4
- CVE-2021-0245A Use of Hard-coded Credentials vulnerability in Juniper Net…7.8
- CVE-2021-0246On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with S…7.3
- CVE-2021-0247A Race Condition (Concurrent Execution using Shared Resource…5.5
- CVE-2021-0248This issue is not applicable to NFX NextGen Software. On NFX…10
- CVE-2021-0250In segment routing traffic engineering (SRTE) environments w…7.5
- CVE-2021-0251A NULL Pointer Dereference vulnerability in the Captive Port…8.6
- CVE-2021-0252NFX Series devices using Juniper Networks Junos OS are susce…7.8
- CVE-2021-0253NFX Series devices using Juniper Networks Junos OS are susce…7.8
- CVE-2021-0254A buffer size validation vulnerability in the overlayd servi…9.8
- CVE-2021-0255A local privilege escalation vulnerability in ethtraceroute …7.8
Are you affected by CVE-2021-0249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
