CVE-2021-31368
Last modified
CVE-2021-31368 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port. Continued receipted of a flood will create a sustained Denial of Service (DoS) condition. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port. Continued receipted of a flood will create a sustained Denial of Service (DoS) condition. Once the flood subsides the system will recover by itself. An indication that the system is affected by this issue would be that kernel and netisr process are shown to be using a lot of CPU cycles like in the following example output: user@host> show system processes extensive ... PID USERNAME PRI NICE SIZE RES STATE C TIME WCPU COMMAND 16 root -72 - 0K 304K WAIT 1 839:40 88.96% intr{swi1: netisr 0} 0 root 97 - 0K 160K RUN 1 732:43 87.99% kernel{bcm560xgmac0 que} This issue affects Juniper Networks JUNOS OS on EX2300 Series, EX3400 Series, and ACX710: All versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8, 18.4R3-S9; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R3-S3; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | < 18.1 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | R1 |
| Juniper | Junos | 20.1 | R1 |
| Juniper | Junos | 20.2 | R1 |
| Juniper | Junos | 20.3 | R1 |
| Juniper | Junos | 20.4 | R1 |
References
- https://kb.juniper.net/JSA11230Vendor Advisory
- https://kb.juniper.net/JSA11230Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31368?
How severe is CVE-2021-31368?
How do I fix CVE-2021-31368?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31362A Protection Mechanism Failure vulnerability in RPD (routing…6.5
- CVE-2021-31363In an MPLS P2MP environment a Loop with Unreachable Exit Con…6.5
- CVE-2021-31364An Improper Check for Unusual or Exceptional Conditions vuln…5.9
- CVE-2021-31365An Uncontrolled Resource Consumption vulnerability in Junipe…6.5
- CVE-2021-31366An Unchecked Return Value vulnerability in the authd (authen…6.5
- CVE-2021-31367A Missing Release of Memory after Effective Lifetime vulnera…6.5
- CVE-2021-31369On MX Series platforms with MS-MPC/MS-MIC, an Allocation of …5.3
- CVE-2021-3137XWiki 12.10.2 allows XSS via an SVG document to the upload f…5.4
- CVE-2021-31370An Incomplete List of Disallowed Inputs vulnerability in Pac…6.5
- CVE-2021-31371Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for in…5.3
- CVE-2021-31372An Improper Input Validation vulnerability in J-Web of Junip…8.8
- CVE-2021-31373A persistent Cross-Site Scripting (XSS) vulnerability in Jun…5.4
Are you affected by CVE-2021-31368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
