CVE-2021-0259
Last modified
CVE-2021-0259 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the overlay network sends a high volume of specific, legitimate traffic in the overlay network, due to an improperly detected DDoS violation, the leaf might not process certain L2 traffic, sent by spines in the underlay network. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the overlay network sends a high volume of specific, legitimate traffic in the overlay network, due to an improperly detected DDoS violation, the leaf might not process certain L2 traffic, sent by spines in the underlay network. Continued receipt and processing of the high volume traffic will sustain the Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on QFX5K Series: 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R2-S8, 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2; 20.3 versions prior to 20.3R1-S2, 20.3R2. Juniper Networks Junos OS Evolved on QFX5220: All versions prior to 20.3R2-EVO.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
| Juniper | Junos | 20.2 | R1 |
| Juniper | Junos | 20.3 | R1 |
| Juniper | Junos Os Evolved | 18.3 | R1 |
| Juniper | Junos Os Evolved | 19.1 | R1 |
| Juniper | Junos Os Evolved | 19.2 | R1 |
| Juniper | Junos Os Evolved | 19.3 | R1 |
| Juniper | Junos Os Evolved | 20.1 | R1 |
| Juniper | Junos Os Evolved | 20.2 | R1 |
| Juniper | Junos Os Evolved | 20.3 | R1 |
References
- https://kb.juniper.net/JSA11150Vendor Advisory
- https://kb.juniper.net/JSA11150Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0259?
How severe is CVE-2021-0259?
How do I fix CVE-2021-0259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0253NFX Series devices using Juniper Networks Junos OS are susce…7.8
- CVE-2021-0254A buffer size validation vulnerability in the overlayd servi…9.8
- CVE-2021-0255A local privilege escalation vulnerability in ethtraceroute …7.8
- CVE-2021-0256A sensitive information disclosure vulnerability in the mosq…5.5
- CVE-2021-0257On Juniper Networks MX Series and EX9200 Series platforms wi…6.5
- CVE-2021-0258A vulnerability in the forwarding of transit TCPv6 packets r…5.9
- CVE-2021-0260An improper authorization vulnerability in the Simple Networ…7.3
- CVE-2021-0261A vulnerability in the HTTP/HTTPS service used by J-Web, Web…7.5
- CVE-2021-0262Through routine static code analysis of the Juniper Networks…6.5
- CVE-2021-0263A Data Processing vulnerability in the Multi-Service process…5.9
- CVE-2021-0264A vulnerability in the processing of traffic matching a fire…7.5
- CVE-2021-0265An unvalidated REST API in the AppFormix Agent of Juniper Ne…8.1
Are you affected by CVE-2021-0259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
