Description
An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending a crafted DHCP packet to the device thereby crashing the jdhcpd DHCP service. This is typically configured for Broadband Subscriber Sessions. Continued receipt and processing of this crafted packet will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS: 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R3; 20.3 versions prior to 20.3R2. This issue does not affect Junos OS Evolved.
No analysis available yet.
Remediation
Vendor Solution
The following software releases have been updated to resolve this specific issue: Junos OS: 19.4R3-S1, 20.1R2-S1, 20.1R3, 20.2R3, 20.3R2, 20.4R1, and all subsequent releases.
Vendor Workaround
There are no viable workarounds for this issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2886 | An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending a crafted DHCP packet to the device thereby crashing the jdhcpd DHCP service. This is typically configured for Broadband Subscriber Sessions. Continued receipt and processing of this crafted packet will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS: 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R3; 20.3 versions prior to 20.3R2. This issue does not affect Junos OS Evolved. |
References
History
No history.
Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2024-09-17T03:54:44.443Z
Reserved: 2020-10-27T00:00:00.000Z
Link: CVE-2021-0267
No data.
Status : Modified
Published: 2021-04-22T20:15:09.910
Modified: 2024-11-21T05:42:21.583
Link: CVE-2021-0267
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD