CVE-2021-0289
Summary
| CVE | CVE-2021-0289 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-15 20:15:00 UTC |
| Updated | 2021-07-28 16:59:00 UTC |
| Description | When user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) interface units, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability between the Device Control Daemon (DCD) and firewall process (dfwd) daemons of Juniper Networks Junos OS allows an attacker to bypass the user-defined ARP Policer. In this particular case the User ARP policer is replaced with default ARP policer. To review the desired ARP Policers and actual state one can run the command "show interfaces <> extensive" and review the output. See further details below. An example output is: show interfaces extensive | match policer Policer: Input: __default_arp_policer__ <<< incorrect if user ARP Policer was applied on an AE interface and the default ARP Policer is displayed Policer: Input: jtac-arp-ae5.317-inet-arp <<< correct if user ARP Policer was applied on an AE interface For all platforms, except SRX Series: This issue affects Juniper Networks Junos OS: All versions 5.6R1 and all later versions prior to 18.4 versions prior to 18.4R2-S9, 18.4R3-S9 with the exception of 15.1 versions 15.1R7-S10 and later versions; 19.4 versions prior to 19.4R3-S3; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R3-S2; 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2; This issue does not affect Juniper Networks Junos OS versions prior to 5.6R1. On SRX Series this issue affects Juniper Networks Junos OS: 18.4 versions prior to 18.4R2-S9, 18.4R3-S9; 19.4 versions prior to 19.4R3-S4; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R3-S2; 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2. This issue does not affect 18.4 versions prior to 18.4R1 on SRX Series. This issue does not affect Junos OS Evolved. |
Risk And Classification
Problem Types: CWE-367
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | Acx1000 | - | All | All | All |
| Hardware | Juniper | Acx1100 | - | All | All | All |
| Hardware | Juniper | Acx2000 | - | All | All | All |
| Hardware | Juniper | Acx2100 | - | All | All | All |
| Hardware | Juniper | Acx2200 | - | All | All | All |
| Hardware | Juniper | Acx4000 | - | All | All | All |
| Hardware | Juniper | Acx500 | - | All | All | All |
| Hardware | Juniper | Acx5000 | - | All | All | All |
| Hardware | Juniper | Acx5048 | - | All | All | All |
| Hardware | Juniper | Acx5096 | - | All | All | All |
| Hardware | Juniper | Acx5400 | - | All | All | All |
| Hardware | Juniper | Acx5448 | - | All | All | All |
| Hardware | Juniper | Acx5800 | - | All | All | All |
| Hardware | Juniper | Acx6300 | - | All | All | All |
| Hardware | Juniper | Acx6360 | - | All | All | All |
| Hardware | Juniper | Acx710 | - | All | All | All |
| Hardware | Juniper | Atp400 | - | All | All | All |
| Hardware | Juniper | Atp700 | - | All | All | All |
| Hardware | Juniper | Csrx | - | All | All | All |
| Hardware | Juniper | Ctp150 | - | All | All | All |
| Hardware | Juniper | Ctp2008 | - | All | All | All |
| Hardware | Juniper | Ctp2024 | - | All | All | All |
| Hardware | Juniper | Ctp2056 | - | All | All | All |
| Hardware | Juniper | Dx | - | All | All | All |
| Hardware | Juniper | Dx | 5.1 | All | All | All |
| Hardware | Juniper | Ex2200 | - | All | All | All |
| Hardware | Juniper | Ex2200-c | - | All | All | All |
| Hardware | Juniper | Ex2200-vc | - | All | All | All |
| Hardware | Juniper | Ex2300 | - | All | All | All |
| Hardware | Juniper | Ex2300-c | - | All | All | All |
| Hardware | Juniper | Ex2300m | - | All | All | All |
| Hardware | Juniper | Ex3200 | - | All | All | All |
| Hardware | Juniper | Ex3300 | - | All | All | All |
| Hardware | Juniper | Ex3300-vc | - | All | All | All |
| Hardware | Juniper | Ex3400 | - | All | All | All |
| Hardware | Juniper | Ex4200 | - | All | All | All |
| Hardware | Juniper | Ex4200-vc | - | All | All | All |
| Hardware | Juniper | Ex4300 | - | All | All | All |
| Hardware | Juniper | Ex4300-24p | - | All | All | All |
| Hardware | Juniper | Ex4300-24p-s | - | All | All | All |
| Hardware | Juniper | Ex4300-24t | - | All | All | All |
| Hardware | Juniper | Ex4300-24t-s | - | All | All | All |
| Hardware | Juniper | Ex4300-32f | - | All | All | All |
| Hardware | Juniper | Ex4300-32f-dc | - | All | All | All |
| Hardware | Juniper | Ex4300-32f-s | - | All | All | All |
| Hardware | Juniper | Ex4300-48mp | - | All | All | All |
| Hardware | Juniper | Ex4300-48mp-s | - | All | All | All |
| Hardware | Juniper | Ex4300-48p | - | All | All | All |
| Hardware | Juniper | Ex4300-48p-s | - | All | All | All |
| Hardware | Juniper | Ex4300-48t | - | All | All | All |
| Hardware | Juniper | Ex4300-48t-afi | - | All | All | All |
| Hardware | Juniper | Ex4300-48t-dc | - | All | All | All |
| Hardware | Juniper | Ex4300-48t-dc-afi | - | All | All | All |
| Hardware | Juniper | Ex4300-48t-s | - | All | All | All |
| Hardware | Juniper | Ex4300-48tafi | - | All | All | All |
| Hardware | Juniper | Ex4300-48tdc | - | All | All | All |
| Hardware | Juniper | Ex4300-48tdc-afi | - | All | All | All |
| Hardware | Juniper | Ex4300-mp | - | All | All | All |
| Hardware | Juniper | Ex4300-vc | - | All | All | All |
| Hardware | Juniper | Ex4300m | - | All | All | All |
| Hardware | Juniper | Ex4400 | - | All | All | All |
| Hardware | Juniper | Ex4500 | - | All | All | All |
| Hardware | Juniper | Ex4500-vc | - | All | All | All |
| Hardware | Juniper | Ex4550 | - | All | All | All |
| Hardware | Juniper | Ex4550-vc | - | All | All | All |
| Hardware | Juniper | Ex4550/vc | - | All | All | All |
| Hardware | Juniper | Ex4600 | - | All | All | All |
| Hardware | Juniper | Ex4600-vc | - | All | All | All |
| Hardware | Juniper | Ex4650 | - | All | All | All |
| Hardware | Juniper | Ex6200 | - | All | All | All |
| Hardware | Juniper | Ex6210 | - | All | All | All |
| Hardware | Juniper | Ex8200 | - | All | All | All |
| Hardware | Juniper | Ex8200-vc | - | All | All | All |
| Hardware | Juniper | Ex8208 | - | All | All | All |
| Hardware | Juniper | Ex8216 | - | All | All | All |
| Hardware | Juniper | Ex9200 | - | All | All | All |
| Hardware | Juniper | Ex9204 | - | All | All | All |
| Hardware | Juniper | Ex9208 | - | All | All | All |
| Hardware | Juniper | Ex9214 | - | All | All | All |
| Hardware | Juniper | Ex9250 | - | All | All | All |
| Hardware | Juniper | Ex9251 | - | All | All | All |
| Hardware | Juniper | Ex9253 | - | All | All | All |
| Hardware | Juniper | Ex Rps | - | All | All | All |
| Hardware | Juniper | Fips Infranet Controller 6500 | - | All | All | All |
| Hardware | Juniper | Fips Secure Access 4000 | - | All | All | All |
| Hardware | Juniper | Fips Secure Access 4500 | - | All | All | All |
| Hardware | Juniper | Fips Secure Access 6000 | - | All | All | All |
| Hardware | Juniper | Fips Secure Access 6500 | - | All | All | All |
| Hardware | Juniper | Gfx3600 | - | All | All | All |
| Hardware | Juniper | Idp250 | - | All | All | All |
| Hardware | Juniper | Idp75 | - | All | All | All |
| Hardware | Juniper | Idp800 | - | All | All | All |
| Hardware | Juniper | Idp8200 | - | All | All | All |
| Hardware | Juniper | Infranet Controller 4000 | - | All | All | All |
| Hardware | Juniper | Infranet Controller 4500 | - | All | All | All |
| Hardware | Juniper | Infranet Controller 6000 | - | All | All | All |
| Hardware | Juniper | Infranet Controller 6500 | - | All | All | All |
| Hardware | Juniper | Jatp | 400 | All | All | All |
| Hardware | Juniper | Jatp | 700 | All | All | All |
| Hardware | Juniper | Junos | - | All | All | All |
| Operating System | Juniper | Junos | All | All | All | All |
| Operating System | Juniper | Junos | 18.4 | - | All | All |
| Operating System | Juniper | Junos | 18.4 | r1 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s3 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s4 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s5 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s6 | All | All |
| Operating System | Juniper | Junos | 18.4 | r1-s7 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s3 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s4 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s5 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s6 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s7 | All | All |
| Operating System | Juniper | Junos | 18.4 | r2-s8 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s4 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s5 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s6 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s7 | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s8 | All | All |
| Operating System | Juniper | Junos | 19.4 | r1 | All | All |
| Operating System | Juniper | Junos | 19.4 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 19.4 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 19.4 | r1-s3 | All | All |
| Operating System | Juniper | Junos | 19.4 | r2 | All | All |
| Operating System | Juniper | Junos | 19.4 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 19.4 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 19.4 | r2-s3 | All | All |
| Operating System | Juniper | Junos | 19.4 | r3 | All | All |
| Operating System | Juniper | Junos | 19.4 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 19.4 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 19.4 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 20.1 | r1 | All | All |
| Operating System | Juniper | Junos | 20.1 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.1 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 20.1 | r1-s3 | All | All |
| Operating System | Juniper | Junos | 20.1 | r1-s4 | All | All |
| Operating System | Juniper | Junos | 20.1 | r2 | All | All |
| Operating System | Juniper | Junos | 20.1 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r2 | All | All |
| Operating System | Juniper | Junos | 20.4 | r1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r2 | All | All |
| Operating System | Juniper | Junos | 20.4 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 5.6 | r1 | All | All |
| Hardware | Juniper | Junos Space Ja1500 Appliance | - | All | All | All |
| Hardware | Juniper | Junos Space Ja2500 Appliance | - | All | All | All |
| Hardware | Juniper | Ln1000 | - | All | All | All |
| Hardware | Juniper | Ln2600 | - | All | All | All |
| Hardware | Juniper | M10i | - | All | All | All |
| Hardware | Juniper | M120 | - | All | All | All |
| Hardware | Juniper | M320 | - | All | All | All |
| Hardware | Juniper | M7i | - | All | All | All |
| Hardware | Juniper | Mag2600 Gateway | - | All | All | All |
| Hardware | Juniper | Mag4610 Gateway | - | All | All | All |
| Hardware | Juniper | Mag6610 Gateway | - | All | All | All |
| Hardware | Juniper | Mag6611 Gateway | - | All | All | All |
| Hardware | Juniper | Mx | - | All | All | All |
| Hardware | Juniper | Mx10 | - | All | All | All |
| Hardware | Juniper | Mx10000 | - | All | All | All |
| Hardware | Juniper | Mx10003 | - | All | All | All |
| Hardware | Juniper | Mx10008 | - | All | All | All |
| Hardware | Juniper | Mx10016 | - | All | All | All |
| Hardware | Juniper | Mx104 | - | All | All | All |
| Hardware | Juniper | Mx150 | - | All | All | All |
| Hardware | Juniper | Mx2008 | - | All | All | All |
| Hardware | Juniper | Mx2010 | - | All | All | All |
| Hardware | Juniper | Mx2020 | - | All | All | All |
| Hardware | Juniper | Mx204 | - | All | All | All |
| Hardware | Juniper | Mx240 | - | All | All | All |
| Hardware | Juniper | Mx40 | - | All | All | All |
| Hardware | Juniper | Mx480 | - | All | All | All |
| Hardware | Juniper | Mx5 | - | All | All | All |
| Hardware | Juniper | Mx80 | - | All | All | All |
| Hardware | Juniper | Mx960 | - | All | All | All |
| Hardware | Juniper | Netscreen-5200 | - | All | All | All |
| Hardware | Juniper | Netscreen-5400 | - | All | All | All |
| Hardware | Juniper | Netscreen-5gt | - | All | All | All |
| Hardware | Juniper | Netscreen-5gt | 5.0 | All | All | All |
| Hardware | Juniper | Netscreen-idp | 3.0 | All | All | All |
| Hardware | Juniper | Netscreen-idp | 3.0r1 | All | All | All |
| Hardware | Juniper | Netscreen-idp | 3.0r2 | All | All | All |
| Hardware | Juniper | Netscreen-idp 10 | - | All | All | All |
| Hardware | Juniper | Netscreen-idp 100 | - | All | All | All |
| Hardware | Juniper | Netscreen-idp 1000 | - | All | All | All |
| Hardware | Juniper | Netscreen-idp 500 | - | All | All | All |
| Hardware | Juniper | Nfx | - | All | All | All |
| Hardware | Juniper | Nfx150 | - | All | All | All |
| Hardware | Juniper | Nfx250 | - | All | All | All |
| Hardware | Juniper | Nfx350 | - | All | All | All |
| Hardware | Juniper | Nsm3000 | - | All | All | All |
| Hardware | Juniper | Nsmexpress | - | All | All | All |
| Hardware | Juniper | Ocx1100 | - | All | All | All |
| Hardware | Juniper | Ptx1000 | - | All | All | All |
| Hardware | Juniper | Ptx1000-72q | - | All | All | All |
| Hardware | Juniper | Ptx10000 | - | All | All | All |
| Hardware | Juniper | Ptx10001 | - | All | All | All |
| Hardware | Juniper | Ptx10001-36mr | - | All | All | All |
| Hardware | Juniper | Ptx100016 | - | All | All | All |
| Hardware | Juniper | Ptx10002 | - | All | All | All |
| Hardware | Juniper | Ptx10002-60c | - | All | All | All |
| Hardware | Juniper | Ptx10003 | - | All | All | All |
| Hardware | Juniper | Ptx10003 160c | - | All | All | All |
| Hardware | Juniper | Ptx10003 80c | - | All | All | All |
| Hardware | Juniper | Ptx10003 81cd | - | All | All | All |
| Hardware | Juniper | Ptx10004 | - | All | All | All |
| Hardware | Juniper | Ptx10008 | - | All | All | All |
| Hardware | Juniper | Ptx10016 | - | All | All | All |
| Hardware | Juniper | Ptx3000 | - | All | All | All |
| Hardware | Juniper | Ptx5000 | - | All | All | All |
| Hardware | Juniper | Qfx10000 | - | All | All | All |
| Hardware | Juniper | Qfx10002 | - | All | All | All |
| Hardware | Juniper | Qfx10002-32q | - | All | All | All |
| Hardware | Juniper | Qfx10002-60c | - | All | All | All |
| Hardware | Juniper | Qfx10002-72q | - | All | All | All |
| Hardware | Juniper | Qfx10008 | - | All | All | All |
| Hardware | Juniper | Qfx10016 | - | All | All | All |
| Hardware | Juniper | Qfx3000-g | - | All | All | All |
| Hardware | Juniper | Qfx3000-m | - | All | All | All |
| Hardware | Juniper | Qfx3008-i | - | All | All | All |
| Hardware | Juniper | Qfx3100 | - | All | All | All |
| Hardware | Juniper | Qfx3500 | - | All | All | All |
| Hardware | Juniper | Qfx3600 | - | All | All | All |
| Hardware | Juniper | Qfx3600-i | - | All | All | All |
| Hardware | Juniper | Qfx5100 | - | All | All | All |
| Hardware | Juniper | Qfx5100-96s | - | All | All | All |
| Hardware | Juniper | Qfx5110 | - | All | All | All |
| Hardware | Juniper | Qfx5120 | - | All | All | All |
| Hardware | Juniper | Qfx5130 | - | All | All | All |
| Hardware | Juniper | Qfx5200 | - | All | All | All |
| Hardware | Juniper | Qfx5200-32c | - | All | All | All |
| Hardware | Juniper | Qfx5200-48y | - | All | All | All |
| Hardware | Juniper | Qfx5210 | - | All | All | All |
| Hardware | Juniper | Qfx5210-64c | - | All | All | All |
| Hardware | Juniper | Qfx5220 | - | All | All | All |
| Hardware | Juniper | Router M10 | - | All | All | All |
| Hardware | Juniper | Router M16 | - | All | All | All |
| Hardware | Juniper | Router M20 | - | All | All | All |
| Hardware | Juniper | Router M40 | - | All | All | All |
| Hardware | Juniper | Router M5 | - | All | All | All |
| Hardware | Juniper | Secure Access 2000 | - | All | All | All |
| Hardware | Juniper | Secure Access 2500 | - | All | All | All |
| Hardware | Juniper | Secure Access 4000 | - | All | All | All |
| Hardware | Juniper | Secure Access 4500 | - | All | All | All |
| Hardware | Juniper | Secure Access 6000 | - | All | All | All |
| Hardware | Juniper | Secure Access 6500 | - | All | All | All |
| Hardware | Juniper | Secure Access 700 | - | All | All | All |
| Hardware | Juniper | Srx100 | - | All | All | All |
| Hardware | Juniper | Srx110 | - | All | All | All |
| Hardware | Juniper | Srx1400 | - | All | All | All |
| Hardware | Juniper | Srx1500 | - | All | All | All |
| Hardware | Juniper | Srx210 | - | All | All | All |
| Hardware | Juniper | Srx220 | - | All | All | All |
| Hardware | Juniper | Srx240 | - | All | All | All |
| Hardware | Juniper | Srx240h2 | - | All | All | All |
| Hardware | Juniper | Srx300 | - | All | All | All |
| Hardware | Juniper | Srx320 | - | All | All | All |
| Hardware | Juniper | Srx340 | - | All | All | All |
| Hardware | Juniper | Srx3400 | - | All | All | All |
| Hardware | Juniper | Srx345 | - | All | All | All |
| Hardware | Juniper | Srx3600 | - | All | All | All |
| Hardware | Juniper | Srx380 | - | All | All | All |
| Hardware | Juniper | Srx4000 | - | All | All | All |
| Hardware | Juniper | Srx4100 | - | All | All | All |
| Hardware | Juniper | Srx4200 | - | All | All | All |
| Hardware | Juniper | Srx4600 | - | All | All | All |
| Hardware | Juniper | Srx5000 | - | All | All | All |
| Hardware | Juniper | Srx5400 | - | All | All | All |
| Hardware | Juniper | Srx550 | - | All | All | All |
| Hardware | Juniper | Srx550m | - | All | All | All |
| Hardware | Juniper | Srx550 Hm | - | All | All | All |
| Hardware | Juniper | Srx5600 | - | All | All | All |
| Hardware | Juniper | Srx5800 | - | All | All | All |
| Hardware | Juniper | Srx650 | - | All | All | All |
| Hardware | Juniper | T1600 | - | All | All | All |
| Hardware | Juniper | T320 | - | All | All | All |
| Hardware | Juniper | T4000 | - | All | All | All |
| Hardware | Juniper | T640 | - | All | All | All |
| Hardware | Juniper | Xre200 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2021-07 Security Bulletin: Junos OS: User-defined ARP Policer isn't applied on Aggregated Ethernet (AE) interface until firewall process is restarted - Juniper Networks | CONFIRM | kb.juniper.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.