CVE detail

CVE-2021-0222 — CVE-2021-0222

Published 2021-01-15 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.4
CVSS v3
0–10 scale
0.0064
EPSS probability
exploitation probability, 30d
47.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets, which should be discarded, are instead replicated and sent to the RE. Over time, a Denial of Service (DoS) occurs. Continued receipt of these crafted protocol packets will cause an extended Denial of Service (DoS) condition, which may cause wider traffic impact due to protocol flapping. An indication of compromise is to check "monitor interface traffic" on the ingress and egress port packet counts. For each ingress packet, two duplicate packets are seen on egress. This issue can be triggered by IPv4 and IPv6 packets. This issue affects all traffic throu

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 14.1X53-D53, 15.1R7-S6, 16.1R7-S7, 17.1R2-S11, 17.2R3-S3, 17.3R2-S5, 17.3R3-S7, 17.4R2-S9, 17.4R3, 18.1R3-S9, 18.2R3-S3, 18.4R1-S5, 18.4R2-S3, 18.4R3, 19.1R1-S4, 19.1R2-S1, 19.1R3, 19.2R2, 19.3R2-S1, 19.3R3, 19.4R1, and all subsequent releases.

workarounds

There are no available workarounds for this issue.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=14.1X53<14.1X53-D5314.1X53-D53advisory ↗
Juniper Networks Junos OS>=15.1<15.1R7-S615.1R7-S6advisory ↗
Juniper Networks Junos OS>=16.1<16.1R7-S716.1R7-S7advisory ↗
Juniper Networks Junos OS>=17.1<17.1R2-S1117.1R2-S11advisory ↗
Juniper Networks Junos OS>=17.1<17.1R3-S217.1R3-S2advisory ↗
Juniper Networks Junos OS>=17.2<17.2R1-S917.2R1-S9advisory ↗
Juniper Networks Junos OS>=17.2<17.2R3-S317.2R3-S3advisory ↗
Juniper Networks Junos OS>=17.3<17.3R2-S5, 17.3R3-S717.3R2-S5, 17.3R3-S7advisory ↗
Juniper Networks Junos OS>=17.4<17.4R2-S9, 17.4R317.4R2-S9, 17.4R3advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S918.1R3-S9advisory ↗
Juniper Networks Junos OS>=18.2<18.2R2-S718.2R2-S7advisory ↗
Juniper Networks Junos OS>=18.2<18.2R3-S318.2R3-S3advisory ↗
Juniper Networks Junos OS>=18.3<18.3R1-S7, 18.3R3-S118.3R1-S7, 18.3R3-S1advisory ↗
Juniper Networks Junos OS>=18.3<18.3R2-S318.3R2-S3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S5, 18.4R2-S3, 18.4R318.4R1-S5, 18.4R2-S3, 18.4R3advisory ↗
Juniper Networks Junos OS>=19.1<19.1R1-S4, 19.1R2-S1, 19.1R319.1R1-S4, 19.1R2-S1, 19.1R3advisory ↗
Juniper Networks Junos OS>=19.2<19.2R1-S3, 19.2R219.2R1-S3, 19.2R2advisory ↗
Juniper Networks Junos OS>=19.2<19.2R1-S4, 19.2R219.2R1-S4, 19.2R2advisory ↗
Juniper Networks Junos OS>=19.3<19.3R1-S1, 19.3R2, 19.3R319.3R1-S1, 19.3R2, 19.3R3advisory ↗
Juniper Networks Junos OS>=19.3<19.3R2-S1, 19.3R319.3R2-S1, 19.3R3advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.