| Summary | A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) allows an attacker to send specially crafted packets to the device, causing the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) process to crash and restart, impacting all traffic going through the FPC, resulting in a Denial of Service (DoS). Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. Following messages will be logged prior to the crash: Feb 2 10:14:39 fpc0 evo-aftmand-bt[16263]: [Error] Nexthop: Failed to get fwd nexthop for nexthop:32710470974358 label:1089551617 for session:18 probe:35 Feb 2 10:14:39 fpc0 evo-aftmand-bt[16263]: [Error] Nexthop: Failed to get fwd nexthop for nexthop:19241453497049 label:1089551617 for session:18 probe:37 Feb 2 10:14:39 fpc0 evo-aftmand-bt[16263]: [Error] Nexthop: Failed to get fwd nexthop for nexthop:19241453497049 label:1089551617 for session:18 probe:44 Feb 2 10:14:39 fpc0 evo-aftmand-bt[16263]: [Error] Nexthop: Failed to get fwd nexthop for nexthop:32710470974358 label:1089551617 for session:18 probe:47 Feb 2 10:14:39 fpc0 audit[16263]: ANOM_ABEND auid=4294967295 uid=0 gid=0 ses=4294967295 pid=16263 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=11 Feb 2 10:14:39 fpc0 kernel: audit: type=1701 audit(1612260879.272:17): auid=4294967295 uid=0 gid=0 ses=4294967295 pid=16263 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=1 This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R2-EVO; 21.1 versions prior to 21.1R2-EVO. |
|---|---|
| Publication Date | July 16, 2021, 5:15 a.m. |
| Registration Date | July 16, 2021, 10 a.m. |
| Last Update | Nov. 21, 2024, 2:42 p.m. |
| CVSS3.1 : HIGH | |
| スコア | 7.5 |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 不要 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 高 |
| CVSS2.0 : HIGH | |
| Score | 7.8 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 不要 |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 高 |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:juniper:junos_os_evolved:19.3:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.3:r2:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.2:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.2:r2:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.3:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:r1-s1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:21.1:r1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.3:-:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.2:-:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:-:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r2-s1:*:*:*:*:*:* | |||||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r2:*:*:*:*:*:* | |||||
| Title | Juniper Networks Junos OS Evolved における例外的な状態のチェックに関する脆弱性 |
|---|---|
| Summary | Juniper Networks Junos OS Evolved (EVO) には、例外的な状態のチェックに関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | July 14, 2021, midnight |
| Registration Date | April 15, 2022, 2:33 p.m. |
| Last Update | April 15, 2022, 2:33 p.m. |
| ジュニパーネットワークス |
| Junos OS Evolved |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2022年03月30日] 掲載 | March 30, 2022, 11:04 a.m. |