CVE detail

CVE-2021-0208 — CVE-2021-0208

Published 2021-01-15 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
8.8
CVSS v3
0–10 scale
0.0065
EPSS probability
exploitation probability, 30d
48.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of Service (DoS) condition. Continued receipt of the packet will sustain the Denial of Service. This issue affects: Juniper Networks Junos OS: All versions prior to 17.3R3-S10 except 15.1X49-D240 for SRX series; 17.4 versions prior to 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R3-S2; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R3-S3; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R2-S

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: Junos OS: 15.1X49-D240, 17.3R3-S10, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S4, 18.3R3-S2, 18.4R1-S8, 18.4R2-S6, 18.4R3-S2, 19.1R1-S5, 19.1R3-S3, 19.2R3, 19.3R2-S5, 19.3R3, 19.4R2-S2, 19.4R3-S1, 20.1R1-S4, 20.1R2, 20.2R1, and all subsequent releases. Note: With the exception of SRX Series products using version 15.1X49-D240, all products using Junos OS prior to 17.3R3-S10 are affected and will not be fixed by Juniper Networks, Inc. Junos OS Evolved: 19.3R2-S5-EVO, 19.4R2-S2-EVO, 20.1R1-S4-EVO, and all subsequent releases.

workarounds

If bidirectional LSPs are running in the network, when changing family mpls maximum-labels on an interface, first disable RSVP for this interface. You can include the disable statement at the following hierarchy levels: [edit protocols rsvp interface interface-name ] [edit logical-systems logical-system-name protocols rsvp interface interface-name ] See the MPLS RSVP disable configuration guide for further details.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=15.1X49<15.1X49-D24015.1X49-D240advisory ↗
Juniper Networks Junos OS>=unspecified<17.3R3-S1017.3R3-S10advisory ↗
Juniper Networks Junos OS>=17.4<17.4R3-S217.4R3-S2advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S1018.1R3-S10advisory ↗
Juniper Networks Junos OS>=18.2<18.2R2-S7, 18.2R3-S418.2R2-S7, 18.2R3-S4advisory ↗
Juniper Networks Junos OS>=18.3<18.3R3-S218.3R3-S2advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S8, 18.4R2-S6, 18.4R3-S218.4R1-S8, 18.4R2-S6, 18.4R3-S2advisory ↗
Juniper Networks Junos OS>=19.1<19.1R1-S5, 19.1R3-S319.1R1-S5, 19.1R3-S3advisory ↗
Juniper Networks Junos OS>=19.2<19.2R319.2R3advisory ↗
Juniper Networks Junos OS>=19.3<19.3R2-S5, 19.3R319.3R2-S5, 19.3R3advisory ↗
Juniper Networks Junos OS>=19.4<19.4R2-S2, 19.4R3-S119.4R2-S2, 19.4R3-S1advisory ↗
Juniper Networks Junos OS>=20.1<20.1R1-S4, 20.1R220.1R1-S4, 20.1R2advisory ↗
Juniper Networks Junos OS Evolved>=19.3<19.3R2-S5-EVO19.3R2-S5-EVOadvisory ↗
Juniper Networks Junos OS Evolved>=19.4<19.4R2-S2-EVO19.4R2-S2-EVOadvisory ↗
Juniper Networks Junos OS Evolved>=20.1<20.1R1-S4-EVO20.1R1-S4-EVOadvisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.