CVE detail

CVE-2021-0261 — CVE-2021-0261

Published 2021-04-22 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.5
CVSS v3
0–10 scale
0.0111
EPSS probability
exploitation probability, 30d
63.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for these services by sending a high number of specific requests. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S17 on EX Series; 12.3X48 versions prior to 12.3X48-D105 on SRX Series; 15.1 versions prior to 15.1R7-S8; 15.1X49 versions prior to 15.1X49-D230 on SRX Series; 16.1 versions prior to 16.1R7-S8; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 v

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 12.3R12-S17, 12.3X48-D105, 15.1R7-S8, 15.1X49-D230, 16.1R7-S8, 17.4R2-S12, 17.4R3-S3, 18.1R3-S11, 18.2R3-S6, 18.3R2-S4, 18.3R3-S3, 18.4R2-S5, 18.4R3-S4, 19.1R2-S2, 19.1R3-S2, 19.2R1-S5, 19.2R3, 19.3R2-S4, 19.3R3, 19.4R1-S3, 19.4R2-S2, 19.4R3, 20.1R1-S3, 20.1R2, 20.2R1-S1, 20.2R2, 20.3R1, and all subsequent releases.

workarounds

There are no viable workarounds for this issue other than disabling the web-service: [deactivate system services web-management] To reduce the risk of exploitation utilize common security BCPs to limit the exploitable surface by limiting access to network and device to trusted systems, administrators, networks and hosts. The 'restart web-management' command can be used to restart the web-service to recover from this issue.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=12.3<12.3R12-S1712.3R12-S17advisory ↗
Juniper Networks Junos OS>=12.3X48<12.3X48-D10512.3X48-D105advisory ↗
Juniper Networks Junos OS>=15.1<15.1R7-S815.1R7-S8advisory ↗
Juniper Networks Junos OS>=15.1X49<15.1X49-D23015.1X49-D230advisory ↗
Juniper Networks Junos OS>=16.1<16.1R7-S816.1R7-S8advisory ↗
Juniper Networks Junos OS>=17.4<17.4R2-S12, 17.4R3-S317.4R2-S12, 17.4R3-S3advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S1118.1R3-S11advisory ↗
Juniper Networks Junos OS>=18.2<18.2R3-S618.2R3-S6advisory ↗
Juniper Networks Junos OS>=18.3<18.3R2-S4, 18.3R3-S318.3R2-S4, 18.3R3-S3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R2-S5, 18.4R3-S418.4R2-S5, 18.4R3-S4advisory ↗
Juniper Networks Junos OS>=19.1<19.1R2-S2, 19.1R3-S219.1R2-S2, 19.1R3-S2advisory ↗
Juniper Networks Junos OS>=19.2<19.2R1-S5, 19.2R319.2R1-S5, 19.2R3advisory ↗
Juniper Networks Junos OS>=19.3<19.3R2-S4, 19.3R319.3R2-S4, 19.3R3advisory ↗
Juniper Networks Junos OS>=19.4<19.4R1-S3, 19.4R2-S2, 19.4R319.4R1-S3, 19.4R2-S2, 19.4R3advisory ↗
Juniper Networks Junos OS>=20.1<20.1R1-S3, 20.1R220.1R1-S3, 20.1R2advisory ↗
Juniper Networks Junos OS>=20.2<20.2R1-S1, 20.2R220.2R1-S1, 20.2R2advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.