Product Affected

This issue affects Junos OS 18.4. Affected platforms: ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX500, ACX5048, ACX5096.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service.

Continued receipt and processing of this specific packet will create a sustained Denial of Service (DoS) condition.

This issue affects only the following platforms in ACX Series:

ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096 devices.

Other ACX platforms are not affected from this issue.

This issue affects Juniper Networks Junos OS on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096:

  • 18.4 version 18.4R3-S7 and later versions prior to 18.4R3-S8.

This issue does not affect:

Juniper Networks Junos OS 18.4 versions prior to 18.4R3-S7 on ACX500, ACX1000, ACX1100, ACX2100, ACX2200, ACX4000, ACX5048, ACX5096.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned CVE-2021-31376 .

Solution

The following software releases have been updated to resolve this specific issue: Junos OS 18.4R3-S8.

This issue is being tracked as 1565716 .

Software releases or updates are available for download at https://support.juniper.net/support/downloads/

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2021-10-13: Initial Publication.

Related Information