Multiple vulnerabilities have been resolved in Juniper Networks Junos OS by fixing vulnerabilities in third party gRPC remote procedure calls (gRPC) stack.
gRPC uses HTTP/2 as its transfer protocol and provides the request/response interface between the Junos extension toolkit (JET) service daemon (JSD) and the on-box or off-box application.
These attack vectors can be used to launch Denial of Service (DoS) attacks against servers that support HTTP/2 communication. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition.
This issue affects:
Juniper Networks Junos OS
This issue does not affect:
Juniper Networks Junos OS versions prior to 16.1R3.
The examples of the config stanza affected by this issue:
[system services extension-service request-response grpc]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during a external security research.
Important security issues resolved include:
The following software releases have been updated to resolve this specific issue: Junos OS: 18.3R2-S4, 18.3R3-S3, 18.4R1-S8, 18.4R2-S5, 18.4R3-S4, 19.1R1-S6, 19.1R2-S2, 19.1R3-S2, 19.2R1-S5, 19.2R2, 19.3R2, 19.4R1, and all subsequent releases.
This issue is being tracked as 1454794 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
Administrator can disable gRPC configuration under "set system services extension-service request-response grpc" hierarchy.
2021-04-14: Initial Publication.