CVE-2021-31375
Last modified
CVE-2021-31375 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may cause RPKI policy-checks to be bypassed. This, in turn, may allow a spoofed advertisement to be accepted or propagated. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may cause RPKI policy-checks to be bypassed. This, in turn, may allow a spoofed advertisement to be accepted or propagated. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S18; 15.1 versions prior to 15.1R7-S9; 17.2 versions prior to 17.2R3-S3; 17.3 versions prior to 17.3R3-S7; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R3-S1; 18.4 versions prior to 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R2; 19.3 versions prior to 19.3R2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 12.3 |
| Juniper | Junos | 15.1 |
| Juniper | Junos | 17.2 |
| Juniper | Junos | 17.3 |
| Juniper | Junos | 17.4 |
| Juniper | Junos | 18.1 |
| Juniper | Junos | 18.2 |
| Juniper | Junos | 18.3 |
| Juniper | Junos | 18.4 |
| Juniper | Junos | 19.1 |
| Juniper | Junos | 19.2 |
| Juniper | Junos | 19.3 |
References
- https://kb.juniper.net/JSA11240Vendor Advisory
- https://kb.juniper.net/JSA11240Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31375?
How severe is CVE-2021-31375?
How do I fix CVE-2021-31375?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3137XWiki 12.10.2 allows XSS via an SVG document to the upload f…5.4
- CVE-2021-31370An Incomplete List of Disallowed Inputs vulnerability in Pac…6.5
- CVE-2021-31371Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for in…5.3
- CVE-2021-31372An Improper Input Validation vulnerability in J-Web of Junip…8.8
- CVE-2021-31373A persistent Cross-Site Scripting (XSS) vulnerability in Jun…5.4
- CVE-2021-31374On Juniper Networks Junos OS and Junos OS Evolved devices pr…7.5
- CVE-2021-31376An Improper Input Validation vulnerability in Packet Forward…7.5
- CVE-2021-31377An Incorrect Permission Assignment for Critical Resource vul…5.5
- CVE-2021-31378In broadband environments, including but not limited to Enha…7.5
- CVE-2021-31379An Incorrect Behavior Order vulnerability in the MAP-E autom…7.5
- CVE-2021-3138In Discourse 2.7.0 through beta1, a rate-limit bypass leads …7.5
- CVE-2021-31380A configuration weakness in the JBoss Application Server (Ap…5.3
Are you affected by CVE-2021-31375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
