CVE-2021-31364 is a denial-of-service vulnerability affecting Juniper Networks Junos OS on specific SRX Series firewalls (SRX300, SRX500, SRX1500, and SRX5000 with SPC2). It stems from a race condition and improper check in the flow daemon (flowd) that can be triggered by unauthenticated attackers sending specific traffic when session-close logging is configured. The vulnerability has a CVSS score of 5.9 (Medium) due to its network-based attack vector, high attack complexity, and high impact on availability, as it can cause a sustained crash of the traffic forwarding process. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.4R3-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.3, < 18.3R3-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 18.4, < 18.4R3-S9CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 19.1, < 19.1R3-S6CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 20.2, < 20.2R3CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.