Product Affected

This issue affects Junos OS 19.4, 20.1, 20.2, 20.3.
High
7.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)

Problem

An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending a crafted DHCP packet to the device thereby crashing the jdhcpd DHCP service. This is typically configured for Broadband Subscriber Sessions.

Continued receipt and processing of this crafted packet will create a sustained Denial of Service (DoS) condition.

This issue affects Juniper Networks Junos OS:

  • 19.4 versions prior to 19.4R3-S1;
  • 20.1 versions prior to 20.1R2-S1, 20.1R3;
  • 20.2 versions prior to 20.2R3;
  • 20.3 versions prior to 20.3R2.

This issue does not affect Junos OS Evolved.

This issue requires active-lease query with none or greater optional settings to be configured in one or more hierarchy locations.

active-leasequery {
idle-timeout "seconds"; (optional)
peer-address "address"; (optional)
timeout "seconds"; (optional)
topology-discover; (optional)
}

with

[forwarding-options dhcp-relay],
[forwarding-options dhcp-relay dhcpv6],
[logical-systems logical-system-name ...],
[logical-systems logical-system-name routing-instances routing-instance-name ...],
[routing-instances routing-instance-name ...]

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned  CVE-2021-0267 .

Solution

The following software releases have been updated to resolve this specific issue:

Junos OS: 19.4R3-S1, 20.1R2-S1, 20.1R3, 20.2R3, 20.3R2, 20.4R1, and all subsequent releases.

This issue is being tracked as  1534814 .

Software releases or updates are available for download at https://support.juniper.net/support/downloads/

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2021-04-14: Initial Publication.

Related Information