CVE-2021-0254
Last modified
CVE-2021-0254 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution (RCE). Continued receipt and processing of these packets will sustain the partial DoS. EPSS estimates a 2.57% chance of exploitation in the next 30 days.
Description
A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution (RCE). Continued receipt and processing of these packets will sustain the partial DoS. The overlayd daemon handles Overlay OAM packets, such as ping and traceroute, sent to the overlay. The service runs as root by default and listens for UDP connections on port 4789. This issue results from improper buffer size validation, which can lead to a buffer overflow. Unauthenticated attackers can send specially crafted packets to trigger this vulnerability, resulting in possible remote code execution. overlayd runs by default in MX Series, ACX Series, and QFX Series platforms. The SRX Series does not support VXLAN and is therefore not vulnerable to this issue. Other platforms are also vulnerable if a Virtual Extensible LAN (VXLAN) overlay network is configured. This issue affects Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R2-S2, 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R2-S1, 20.2R3; 20.3 versions prior to 20.3R1-S1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 15.1 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
| Juniper | Junos | 20.2 | R1 |
| Juniper | Junos | 20.3 | R1 |
References
- https://kb.juniper.net/JSA11147Vendor Advisory
- https://kb.juniper.net/JSA11147Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0254?
How severe is CVE-2021-0254?
How do I fix CVE-2021-0254?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0248This issue is not applicable to NFX NextGen Software. On NFX…10
- CVE-2021-0249On SRX Series devices configured with UTM services a buffer …9.8
- CVE-2021-0250In segment routing traffic engineering (SRTE) environments w…7.5
- CVE-2021-0251A NULL Pointer Dereference vulnerability in the Captive Port…8.6
- CVE-2021-0252NFX Series devices using Juniper Networks Junos OS are susce…7.8
- CVE-2021-0253NFX Series devices using Juniper Networks Junos OS are susce…7.8
- CVE-2021-0255A local privilege escalation vulnerability in ethtraceroute …7.8
- CVE-2021-0256A sensitive information disclosure vulnerability in the mosq…5.5
- CVE-2021-0257On Juniper Networks MX Series and EX9200 Series platforms wi…6.5
- CVE-2021-0258A vulnerability in the forwarding of transit TCPv6 packets r…5.9
- CVE-2021-0259Due to a vulnerability in DDoS protection in Juniper Network…7.4
- CVE-2021-0260An improper authorization vulnerability in the Simple Networ…7.3
Are you affected by CVE-2021-0254?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
