CVE detail

CVE-2021-0244 — CVE-2021-0244

Published 2021-04-22 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.4
CVSS v3
0–10 scale
0.0064
EPSS probability
exploitation probability, 30d
47.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the storm-control feature on devices. This issue is a corner case and only occurs during specific actions taken by an administrator of a device under certain specifics actions which triggers the event. The event occurs less frequently on devices which are not configured with Virtual Chassis configurations, and more frequently on devices configured in Virtual Chassis configurations. This issue is not specific to any particular Junos OS platform. An Indicator of Compromise (IoC) may be seen by reviewing log files for the following error message seen by executing

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 14.1X53-D49, 15.1R7-S6, 15.1X49-D191, 15.1X49-D200, 15.1X53-D592, 16.1R7-S7, 16.1R8, 16.2R2-S11, 16.2R3, 17.1R2-S11, 17.1R3, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S7, 17.4R2-S9, 17.4R3, 18.1R3-S5, 18.2R2-S6, 18.2R3, 18.3R1-S7, 18.3R2-S3, 18.3R3, 18.4R1-S5, 18.4R2, 19.1R1-S4, 19.1R2, 19.2R1, and all subsequent releases.

workarounds

There are no viable workarounds for this issue other than rebooting the device and monitoring for the Indicator of Compromise (IoC). Once the condition is cleared from the log files - the absence of the error message indicates the condition has cleared - the device is not exploitable to the situation, and the actions taken which lead to the IoC being present should not be taken again, until a fixed release can be applied.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=14.1X53<14.1X53-D4914.1X53-D49advisory ↗
Juniper Networks Junos OS>=15.1<15.1R7-S615.1R7-S6advisory ↗
Juniper Networks Junos OS>=15.1X49<15.1X49-D191, 15.1X49-D20015.1X49-D191, 15.1X49-D200advisory ↗
Juniper Networks Junos OS>=16.1<16.1R7-S716.1R7-S7advisory ↗
Juniper Networks Junos OS>=16.2<16.2R2-S11, 16.2R316.2R2-S11, 16.2R3advisory ↗
Juniper Networks Junos OS>=17.1<17.1R2-S11, 17.1R317.1R2-S11, 17.1R3advisory ↗
Juniper Networks Junos OS>=17.2<17.2R2-S8, 17.2R3-S317.2R2-S8, 17.2R3-S3advisory ↗
Juniper Networks Junos OS>=17.3<17.3R2-S5, 17.3R3-S717.3R2-S5, 17.3R3-S7advisory ↗
Juniper Networks Junos OS>=17.4<17.4R2-S9, 17.4R317.4R2-S9, 17.4R3advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S518.1R3-S5advisory ↗
Juniper Networks Junos OS>=18.2<18.2R2-S6, 18.2R318.2R2-S6, 18.2R3advisory ↗
Juniper Networks Junos OS>=18.3<18.3R1-S7, 18.3R2-S3, 18.3R318.3R1-S7, 18.3R2-S3, 18.3R3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S5, 18.4R218.4R1-S5, 18.4R2advisory ↗
Juniper Networks Junos OS>=19.1<19.1R1-S4, 19.1R219.1R1-S4, 19.1R2advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.