CVE-2021-0254 is a critical buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS, affecting MX, ACX, and QFX Series platforms, and other platforms with configured VXLAN. This flaw allows unauthenticated remote attackers to send specially crafted packets, leading to a partial Denial of Service or potential remote code execution. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, posing a high risk of complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.1, < 15.1R7-S9CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 17.3, < 17.3R3-S11CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.1, < 18.1R3-S12CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.3, < 18.3R3-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 19.3, < 19.3R3-S1CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.