CVE-2021-0233CWE-400CWE-794

Junos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.

High · published April 22, 2021

CVSS v3.1
7.5
EPSS
1%
Percentile
59.3
In the wild
Unconfirmed
What it is

A vulnerability in Juniper Networks Junos OS ACX500 Series, ACX4000 Series, may allow an attacker to cause a Denial of Service (DoS) by sending a high rate of specific packets to the device, resulting in a Forwarding Engine Board (FFEB) crash. Continued receipt of these packets will sustain the Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS on ACX500 Series, ACX4000 Series: 17.4 versions prior to 17.4R3-S2.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00961 · 59.3th percentile
Weaknesses
CWE-400 · Uncontrolled Resource Consumption; CWE-794 · Incomplete Filtering of Multiple Instances of Special Elements
Published
2021-04-22T19:37Z
EPSS history
Timeline
  • 22 APR 19:37Z
    Junos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.
    cvelistv5