CVE Feed

    Dashboard / CVE / CVE-2021-0261

    CVE-2021-0261

    A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for these services by sending a high number of specific requests. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S17 on EX Series; 12.3X48 versions prior to 12.3X48-D105 on SRX Series; 15.1 versions prior to 15.1R7-S8; 15.1X49 versions prior to 15.1X49-D230 on SRX Series; 16.1 versions prior to 16.1R7-S8; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R2-S2, 19.1R3-S2; 19.2 versions prior to 19.2R1-S5, 19.2R3; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R1-S3, 20.1R2; 20.2 versions prior to 20.2R1-S1, 20.2R2.

    Published:Apr 22, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 22, 2021
    EPSS Score:0.00438
    CVSS Score:7.5

    Affected Products

    Vendor
    Juniper
    Product
    Ex2300
    Vendor
    Juniper
    Product
    Ex2300-c
    Vendor
    Juniper
    Product
    Ex3400
    Vendor
    Juniper
    Product
    Ex4300
    Vendor
    Juniper
    Product
    Ex4400
    Vendor
    Juniper
    Product
    Ex4600
    Vendor
    Juniper
    Product
    Ex4650
    Vendor
    Juniper
    Product
    Ex9200
    Vendor
    Juniper
    Product
    Ex9250
    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper
    Product
    Srx1500
    Vendor
    Juniper
    Product
    Srx300
    Vendor
    Juniper
    Product
    Srx320
    Vendor
    Juniper
    Product
    Srx340
    Vendor
    Juniper
    Product
    Srx345
    Vendor
    Juniper
    Product
    Srx380
    Vendor
    Juniper
    Product
    Srx4100
    Vendor
    Juniper
    Product
    Srx4200
    Vendor
    Juniper
    Product
    Srx4600
    Vendor
    Juniper
    Product
    Srx5400
    Vendor
    Juniper
    Product
    Srx550
    Vendor
    Juniper
    Product
    Srx5600
    Vendor
    Juniper
    Product
    Srx5800

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High