CVE-2021-31376
Summary
| CVE | CVE-2021-31376 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-19 19:15:00 UTC |
| Updated | 2021-10-25 16:20:00 UTC |
| Description | An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Continued receipt and processing of this specific packet will create a sustained Denial of Service (DoS) condition. This issue affects only the following platforms in ACX Series: ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096 devices. Other ACX platforms are not affected from this issue. This issue affects Juniper Networks Junos OS on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096: 18.4 version 18.4R3-S7 and later versions prior to 18.4R3-S8. This issue does not affect: Juniper Networks Junos OS 18.4 versions prior to 18.4R3-S7 on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | Acx1000 | - | All | All | All |
| Hardware | Juniper | Acx1100 | - | All | All | All |
| Hardware | Juniper | Acx2100 | - | All | All | All |
| Hardware | Juniper | Acx2200 | - | All | All | All |
| Hardware | Juniper | Acx4000 | - | All | All | All |
| Hardware | Juniper | Acx500 | - | All | All | All |
| Hardware | Juniper | Acx5048 | - | All | All | All |
| Hardware | Juniper | Acx5096 | - | All | All | All |
| Operating System | Juniper | Junos | 18.4 | r3-s7 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2021-10 Security Bulletin: Junos OS: ACX Series: Packet Forwarding Engine manager (FXPC) process crashes when processing DHCPv6 packets (CVE-2021-31376) - Juniper Networks | CONFIRM | kb.juniper.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.