{"containers":{"cna":{"affected":[{"product":"Junos OS","vendor":"Juniper Networks","versions":[{"lessThan":"19.3R3-S2","status":"unaffected","version":"unspecified","versionType":"custom"},{"status":"affected","version":"19.3R3-S2"},{"status":"affected","version":"19.4R3-S3"},{"lessThan":"20.1*","status":"unaffected","version":"20.1R1","versionType":"custom"},{"changes":[{"at":"20.2R3-S2","status":"unaffected"}],"lessThan":"20.2R2-S3","status":"unaffected","version":"20.2","versionType":"custom"},{"changes":[{"at":"20.3R3","status":"unaffected"}],"lessThan":"20.3R2","status":"unaffected","version":"20.3","versionType":"custom"},{"changes":[{"at":"20.4R3","status":"unaffected"}],"lessThan":"20.4R2","status":"unaffected","version":"20.4","versionType":"custom"},{"lessThan":"21.1R2","status":"affected","version":"21.1","versionType":"custom"}]},{"product":"Junos OS Evolved","vendor":"Juniper Networks","versions":[{"lessThan":"20.4R2-S3-EVO, 20.4R3-EVO","status":"affected","version":"unspecified","versionType":"custom"},{"lessThan":"21.1R2-EVO","status":"affected","version":"21.1-EVO","versionType":"custom"},{"lessThan":"21.2R2-EVO","status":"affected","version":"21.2-EVO","versionType":"custom"}]}],"configurations":[{"lang":"en","value":"This issue can occur when multipath is enabled:\n\n  routing-instance <vrf> routing-options multipath\n\nand one of the following two TTL propagation options (but not both) are enabled:\n\n  protocols mpls no-propagate-ttl\n  routing-instance <vrf> no-vrf-propagate-ttl"}],"datePublic":"2021-10-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued receipt and processing of the BGP update will create a sustained Denial of Service (DoS) condition. This issue affects very specific versions of Juniper Networks Junos OS: 19.3R3-S2; 19.4R3-S3; 20.2 versions 20.2R2-S3 and later, prior to 20.2R3-S2; 20.3 versions 20.3R2 and later, prior to 20.3R3; 20.4 versions 20.4R2 and later, prior to 20.4R3; 21.1 versions prior to 21.1R2. Juniper Networks Junos OS 20.1 is not affected by this issue. This issue also affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R2-S3-EVO, 20.4R3-EVO; 21.1-EVO versions prior to 21.1R2-EVO; 21.2-EVO versions prior to 21.2R2-EVO."}],"exploits":[{"lang":"en","value":"Juniper SIRT is not aware of any malicious exploitation of this vulnerability."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-755","description":"CWE-755 Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2021-10-19T18:16:34.000Z","orgId":"8cbe9d5a-a066-4c94-8978-4b15efeae968","shortName":"juniper"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kb.juniper.net/JSA11218"}],"solutions":[{"lang":"en","value":"The following software releases have been updated to resolve this specific issue: \n\nJunos OS 18.4R2-S9, 19.1R3-S7, 19.3R3-S3, 19.4R1-S4, 19.4R3-S4, 20.1R3, 20.2R3-S2, 20.3R3, 20.4R3, 21.1R2, 21.2R1, 21.2R2, 21.3R1, and all subsequent releases.\n\nJunos OS Evolved 20.4R2-S3-EVO, 20.4R3-EVO, 21.1R2-EVO, 21.2R2-EVO, 21.3R1-EVO, and all subsequent releases.\n\nNote: Only those releases listed in the PROBLEM section above are affected.  This fix has also been proactively committed into other releases that are not vulnerable to this issue."}],"source":{"advisory":"JSA11218","defect":["1595165"],"discovery":"USER"},"title":"Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update","workarounds":[{"lang":"en","value":"This issue can be mitigated in two ways:\n\n1) ensure that TTL propagation is either enabled or disabled in both places below:\n  protocols mpls no-propagate-ttl\n  routing-instance <vrf> no-vrf-propagate-ttl\n\n2) Disable multipath:\n  routing-instance <vrf> routing-options multipath"}],"x_generator":{"engine":"Vulnogram 0.0.9"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"sirt@juniper.net","DATE_PUBLIC":"2021-10-13T16:00:00.000Z","ID":"CVE-2021-31353","STATE":"PUBLIC","TITLE":"Junos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Junos OS","version":{"version_data":[{"version_affected":"!<","version_value":"19.3R3-S2"},{"version_affected":"=","version_value":"19.3R3-S2"},{"version_affected":"=","version_value":"19.4R3-S3"},{"version_affected":"!>=","version_name":"20.1","version_value":"20.1R1"},{"version_affected":"!<","version_name":"20.2","version_value":"20.2R2-S3"},{"version_affected":"<","version_name":"20.2","version_value":"20.2R3-S2"},{"version_affected":"!<","version_name":"20.3","version_value":"20.3R2"},{"version_affected":"<","version_name":"20.3","version_value":"20.3R3"},{"version_affected":"!<","version_name":"20.4","version_value":"20.4R2"},{"version_affected":"<","version_name":"20.4","version_value":"20.4R3"},{"version_affected":"<","version_name":"21.1","version_value":"21.1R2"}]}},{"product_name":"Junos OS Evolved","version":{"version_data":[{"version_affected":"<","version_value":"20.4R2-S3-EVO, 20.4R3-EVO"},{"version_affected":"<","version_name":"21.1-EVO","version_value":"21.1R2-EVO"},{"version_affected":"<","version_name":"21.2-EVO","version_value":"21.2R2-EVO"}]}}]},"vendor_name":"Juniper Networks"}]}},"configuration":[{"lang":"en","value":"This issue can occur when multipath is enabled:\n\n  routing-instance <vrf> routing-options multipath\n\nand one of the following two TTL propagation options (but not both) are enabled:\n\n  protocols mpls no-propagate-ttl\n  routing-instance <vrf> no-vrf-propagate-ttl"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued receipt and processing of the BGP update will create a sustained Denial of Service (DoS) condition. This issue affects very specific versions of Juniper Networks Junos OS: 19.3R3-S2; 19.4R3-S3; 20.2 versions 20.2R2-S3 and later, prior to 20.2R3-S2; 20.3 versions 20.3R2 and later, prior to 20.3R3; 20.4 versions 20.4R2 and later, prior to 20.4R3; 21.1 versions prior to 21.1R2. Juniper Networks Junos OS 20.1 is not affected by this issue. This issue also affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R2-S3-EVO, 20.4R3-EVO; 21.1-EVO versions prior to 21.1R2-EVO; 21.2-EVO versions prior to 21.2R2-EVO."}]},"exploit":[{"lang":"en","value":"Juniper SIRT is not aware of any malicious exploitation of this vulnerability."}],"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-755 Improper Handling of Exceptional Conditions"}]}]},"references":{"reference_data":[{"name":"https://kb.juniper.net/JSA11218","refsource":"CONFIRM","url":"https://kb.juniper.net/JSA11218"}]},"solution":[{"lang":"en","value":"The following software releases have been updated to resolve this specific issue: \n\nJunos OS 18.4R2-S9, 19.1R3-S7, 19.3R3-S3, 19.4R1-S4, 19.4R3-S4, 20.1R3, 20.2R3-S2, 20.3R3, 20.4R3, 21.1R2, 21.2R1, 21.2R2, 21.3R1, and all subsequent releases.\n\nJunos OS Evolved 20.4R2-S3-EVO, 20.4R3-EVO, 21.1R2-EVO, 21.2R2-EVO, 21.3R1-EVO, and all subsequent releases.\n\nNote: Only those releases listed in the PROBLEM section above are affected.  This fix has also been proactively committed into other releases that are not vulnerable to this issue."}],"source":{"advisory":"JSA11218","defect":["1595165"],"discovery":"USER"},"work_around":[{"lang":"en","value":"This issue can be mitigated in two ways:\n\n1) ensure that TTL propagation is either enabled or disabled in both places below:\n  protocols mpls no-propagate-ttl\n  routing-instance <vrf> no-vrf-propagate-ttl\n\n2) Disable multipath:\n  routing-instance <vrf> routing-options multipath"}]}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T22:55:53.456Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kb.juniper.net/JSA11218"}]}]},"cveMetadata":{"assignerOrgId":"8cbe9d5a-a066-4c94-8978-4b15efeae968","assignerShortName":"juniper","cveId":"CVE-2021-31353","datePublished":"2021-10-19T18:16:34.884Z","dateReserved":"2021-04-15T00:00:00.000Z","dateUpdated":"2024-09-16T17:37:46.150Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}