CVE-2021-0254 Details
Description
A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remote code execution (RCE). Continued receipt and processing of these packets will sustain the partial DoS. The overlayd daemon handles Overlay OAM packets, such as ping and traceroute, sent to the overlay. The service runs as root by default and listens for UDP connections on port 4789. This issue results from improper buffer size validation, which can lead to a buffer overflow. Unauthenticated attackers can send specially crafted packets to trigger this vulnerability, resulting in possible remote code execution. overlayd runs by default in MX Series, ACX Series, and QFX Series platforms. The SRX Series does not support VXLAN and is therefore not vulnerable to this issue. Other platforms are also vulnerable if a Virtual Extensible LAN (VXLAN) overlay network is configured. This issue affects Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S7; 19.1 versions prior to 19.1R2-S2, 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S2; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R2, 20.2R2-S1, 20.2R3; 20.3 versions prior to 20.3R1-S1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA11147 | CVE | Vendor Advisory |
| https://kb.juniper.net/JSA11147 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-131 | Incorrect Calculation of Buffer Size | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 15.1 - 15.1 a1 15.1 f 15.1 f1 15.1 f2 15.1 f2-s1 15.1 f2-s2 15.1 f2-s3 15.1 f2-s4 15.1 f3 15.1 f4 15.1 f5 15.1 f5-s7 15.1 f6 15.1 f6-s1 15.1 f6-s10 15.1 f6-s12 15.1 f6-s2 15.1 f6-s3 15.1 f6-s4 15.1 f6-s5 15.1 f6-s6 15.1 f6-s7 15.1 f6-s8 15.1 f6-s9 15.1 f7 15.1 r 15.1 r1 15.1 r2 15.1 r3 15.1 r4 15.1 r4-s7 15.1 r4-s8 15.1 r4-s9 15.1 r5 15.1 r5-s1 15.1 r5-s3 15.1 r5-s5 15.1 r5-s6 15.1 r6 15.1 r6-s1 15.1 r6-s2 15.1 r6-s3 15.1 r6-s4 15.1 r6-s6 15.1 r7 15.1 r7-s1 15.1 r7-s2 15.1 r7-s3 15.1 r7-s4 15.1 r7-s5 15.1 r7-s6 15.1 r7-s7 15.1 r7-s8 17.3 - 17.3 r1 17.3 r1-s1 17.3 r1-s4 17.3 r2 17.3 r2-s1 17.3 r2-s2 17.3 r2-s3 17.3 r2-s4 17.3 r2-s5 17.3 r3 17.3 r3-s1 17.3 r3-s10 17.3 r3-s2 17.3 r3-s3 17.3 r3-s4 17.3 r3-s5 17.3 r3-s6 17.3 r3-s7 17.3 r3-s8 17.3 r3-s9 17.4 - 17.4 r1 17.4 r1-s1 17.4 r1-s2 17.4 r1-s3 17.4 r1-s4 17.4 r1-s5 17.4 r1-s6 17.4 r1-s7 17.4 r2 17.4 r2-s1 17.4 r2-s10 17.4 r2-s11 17.4 r2-s12 17.4 r2-s2 17.4 r2-s3 17.4 r2-s4 17.4 r2-s5 17.4 r2-s6 17.4 r2-s7 17.4 r2-s8 17.4 r2-s9 17.4 r3 17.4 r3-s1 17.4 r3-s2 17.4 r3-s3 18.1 - 18.1 r1 18.1 r2 18.1 r2-s1 18.1 r2-s2 18.1 r2-s4 18.1 r3 18.1 r3-s1 18.1 r3-s10 18.1 r3-s11 18.1 r3-s2 18.1 r3-s3 18.1 r3-s4 18.1 r3-s5 18.1 r3-s6 18.1 r3-s7 18.1 r3-s8 18.1 r3-s9 18.2 - 18.2 r1 18.2 r1-s2 18.2 r1-s3 18.2 r1-s4 18.2 r1-s5 18.2 r2 18.2 r2-s1 18.2 r2-s2 18.2 r2-s3 18.2 r2-s4 18.2 r2-s5 18.2 r2-s6 18.2 r2-s7 18.2 r3 18.2 r3-s1 18.2 r3-s2 18.2 r3-s3 18.2 r3-s4 18.2 r3-s5 18.2 r3-s6 18.3 - 18.3 r1 18.3 r1-s1 18.3 r1-s2 18.3 r1-s3 18.3 r1-s4 18.3 r1-s5 18.3 r1-s6 18.3 r2 18.3 r2-s1 18.3 r2-s2 18.3 r2-s3 18.3 r2-s4 18.3 r3 18.3 r3-s1 18.3 r3-s2 18.3 r3-s3 18.4 - 18.4 r1 18.4 r1-s1 18.4 r1-s2 18.4 r1-s3 18.4 r1-s4 18.4 r1-s5 18.4 r1-s6 18.4 r1-s7 18.4 r2 18.4 r2-s1 18.4 r2-s2 18.4 r2-s3 18.4 r2-s4 18.4 r2-s5 18.4 r2-s6 18.4 r3 18.4 r3-s1 18.4 r3-s2 18.4 r3-s3 18.4 r3-s4 18.4 r3-s5 18.4 r3-s6 19.1 - 19.1 r1 19.1 r1-s1 19.1 r1-s2 19.1 r1-s3 19.1 r1-s4 19.1 r1-s5 19.1 r2 19.1 r2-s1 19.1 r3 19.1 r3-s1 19.1 r3-s2 19.1 r3-s3 19.2 - 19.2 r1 19.2 r1-s1 19.2 r1-s2 19.2 r1-s3 19.2 r1-s4 19.2 r1-s5 19.2 r2 19.2 r2-s1 19.2 r3 19.2 r3-s1 19.3 - 19.3 r1 19.3 r1-s1 19.3 r2 19.3 r2-s1 19.3 r2-s2 19.3 r2-s3 19.3 r2-s4 19.3 r2-s5 19.3 r3 19.4 r1 19.4 r1-s1 19.4 r1-s2 19.4 r2 19.4 r2-s1 19.4 r2-s2 19.4 r2-s3 19.4 r3 20.1 r1 20.1 r1-s1 20.1 r1-s2 20.1 r1-s3 20.1 r1-s4 20.1 r2 20.2 r1 20.2 r1-s1 20.2 r1-s2 20.2 r1-s3 20.2 r2 20.3 r1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 5, 2022 | Reanalysis | [email protected] |
| Apr 27, 2021 | Initial Analysis | [email protected] |