CVE Feed

    Dashboard / CVE / CVE-2021-31361

    CVE-2021-31361

    An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CPU utilization by sending specific IP packets which are being VXLAN encapsulated leading to a partial Denial of Service (DoS). Continued receipted of these specific traffic will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on QFX Series: All versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S3, 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R3; 20.3 versions prior to 20.3R1-S1, 20.3R2. Juniper Networks Junos OS on PTX Series: All versions prior to 18.4R3-S9; 19.1 versions prior to 19.1R3-S6; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R1-S4, 19.4R3-S5; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3-S1; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2.

    Published:Oct 19, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 19, 2021
    EPSS Score:0.00458
    CVSS Score:5.3

    Affected Products

    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper
    Product
    Ptx1000
    Vendor
    Juniper
    Product
    Ptx1000-72q
    Vendor
    Juniper
    Product
    Ptx10000
    Vendor
    Juniper
    Product
    Ptx10001
    Vendor
    Juniper
    Product
    Ptx10001-36mr
    Vendor
    Juniper
    Product
    Ptx100016
    Vendor
    Juniper
    Product
    Ptx10002
    Vendor
    Juniper
    Product
    Ptx10002-60c
    Vendor
    Juniper
    Product
    Ptx10003
    Vendor
    Juniper
    Product
    Ptx10003 160c
    Vendor
    Juniper
    Product
    Ptx10003 80c
    Vendor
    Juniper
    Product
    Ptx10003 81cd
    Vendor
    Juniper
    Product
    Ptx10004
    Vendor
    Juniper
    Product
    Ptx10008
    Vendor
    Juniper
    Product
    Ptx10016
    Vendor
    Juniper
    Product
    Ptx3000
    Vendor
    Juniper
    Product
    Ptx5000
    Vendor
    Juniper
    Product
    Qfx10000
    Vendor
    Juniper
    Product
    Qfx10002
    Vendor
    Juniper
    Product
    Qfx10002-32q
    Vendor
    Juniper
    Product
    Qfx10002-60c
    Vendor
    Juniper
    Product
    Qfx10002-72q
    Vendor
    Juniper
    Product
    Qfx10008
    Vendor
    Juniper
    Product
    Qfx10016
    Vendor
    Juniper
    Product
    Qfx10k
    Vendor
    Juniper
    Product
    Qfx3000-g
    Vendor
    Juniper
    Product
    Qfx3000-m
    Vendor
    Juniper
    Product
    Qfx3008-i
    Vendor
    Juniper
    Product
    Qfx3100
    Vendor
    Juniper
    Product
    Qfx3500
    Vendor
    Juniper
    Product
    Qfx3600
    Vendor
    Juniper
    Product
    Qfx3600-i
    Vendor
    Juniper
    Product
    Qfx5100
    Vendor
    Juniper
    Product
    Qfx5100-96s
    Vendor
    Juniper
    Product
    Qfx5110
    Vendor
    Juniper
    Product
    Qfx5120
    Vendor
    Juniper
    Product
    Qfx5130
    Vendor
    Juniper
    Product
    Qfx5200
    Vendor
    Juniper
    Product
    Qfx5200-32c
    Vendor
    Juniper
    Product
    Qfx5200-48y
    Vendor
    Juniper
    Product
    Qfx5210
    Vendor
    Juniper
    Product
    Qfx5210-64c
    Vendor
    Juniper
    Product
    Qfx5220

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High