Product Affected

This issue affects SBR Carrier 8.4.1, 8.5.0, 8.6.0.
Critical
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Problem

A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the radius daemon, causing a sustained Denial of Service (DoS).

This issue affects Juniper Networks SBR Carrier:

  • 8.4.1 versions prior to 8.4.1R19;
  • 8.5.0 versions prior to 8.5.0R10;
  • 8.6.0 versions prior to 8.6.0R4.

This issue affects SBR Carrier with EAP authentication configured only when using Enhanced EAP Logging and TraceLevel setting of 2.

<SBR_Installed_Directory> /JNPRsbr/radius/radius.ini
[Logging]
LogLevel=2
TraceLevel=2
EnhancedEAPLogging = yes

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned CVE-2021-0276 .

Solution

The following software releases have been updated to resolve this specific issue: 8.4.1R19, 8.5.0R10, 8.6.0R4 and all subsequent releases.

This issue is being tracked as 1465201 .

Software releases or updates are available for download at https://support.juniper.net/support/downloads/
 

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2021-07-14: Initial Publication.

Related Information