CVE-2021-0272
Last modified
CVE-2021-0272 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A kernel memory leak in QFX10002-32Q, QFX10002-60C, QFX10002-72Q, QFX10008, QFX10016 devices Flexible PIC Concentrators (FPCs) on Juniper Networks Junos OS allows an attacker to send genuine packets destined to the device to cause a Denial of Service (DoS) to the device. On QFX10002-32Q, QFX10002-60C, QFX10002-72Q devices the device will crash and restart. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
A kernel memory leak in QFX10002-32Q, QFX10002-60C, QFX10002-72Q, QFX10008, QFX10016 devices Flexible PIC Concentrators (FPCs) on Juniper Networks Junos OS allows an attacker to send genuine packets destined to the device to cause a Denial of Service (DoS) to the device. On QFX10002-32Q, QFX10002-60C, QFX10002-72Q devices the device will crash and restart. On QFX10008, QFX10016 devices, depending on the number of FPCs involved in an attack, one more more FPCs may crash and traffic through the device may be degraded in other ways, until the attack traffic stops. A reboot is required to restore service and clear the kernel memory. Continued receipt and processing of these genuine packets will create a sustained Denial of Service (DoS) condition. On QFX10008, QFX10016 devices, an indicator of compromise may be the existence of DCPFE core files. You can also monitor PFE memory utilization for incremental growth: user@qfx-RE:0% cprod -A fpc0 -c "show heap 0" | grep -i ke 0 3788a1b0 3221225048 2417120656 804104392 24 Kernel user@qfx-RE:0% cprod -A fpc0 -c "show heap 0" | grep -i ke 0 3788a1b0 3221225048 2332332200 888892848 27 Kernel This issue affects: Juniper Networks Junos OS on QFX10002-32Q, QFX10002-60C, QFX10002-72Q, QFX10008, QFX10016: 16.1 versions 16.1R1 and above prior to 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R3-S2; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R3-S2; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R3; 19.4 versions prior to 19.4R3; 20.1 versions prior to 20.1R2. This issue does not affect releases prior to Junos OS 16.1R1. This issue does not affect EX Series devices. This issue does not affect Junos OS Evolved.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 16.1 | R1 |
| Juniper | Junos | 16.2 | — |
| Juniper | Junos | 17.1 | — |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
References
- https://kb.juniper.net/JSA11163Vendor Advisory
- https://kb.juniper.net/KB32854Vendor Advisory
- https://kb.juniper.net/JSA11163Vendor Advisory
- https://kb.juniper.net/KB32854Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0272?
How severe is CVE-2021-0272?
How do I fix CVE-2021-0272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0266The use of multiple hard-coded cryptographic keys in cSRX Se…9.8
- CVE-2021-0267An Improper Input Validation vulnerability in the active-lea…6.5
- CVE-2021-0268An Improper Neutralization of CRLF Sequences in HTTP Headers…9.3
- CVE-2021-0269The improper handling of client-side parameters in J-Web of …8.8
- CVE-2021-0270On PTX Series and QFX10k Series devices with the "inline-jfl…5.9
- CVE-2021-0271A Double Free vulnerability in the software forwarding inter…6.5
- CVE-2021-0273An always-incorrect control flow implementation in the impli…5.3
- CVE-2021-0275A Cross-site Scripting (XSS) vulnerability in J-Web on Junip…8.8
- CVE-2021-0276A stack-based Buffer Overflow vulnerability in Juniper Netwo…9.8
- CVE-2021-0277An Out-of-bounds Read vulnerability in the processing of spe…8.8
- CVE-2021-0278An Improper Input Validation vulnerability in J-Web of Junip…7.8
- CVE-2021-0279Juniper Networks Contrail Cloud (CC) releases prior to 13.6.…5.5
Are you affected by CVE-2021-0272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
