// For flags

CVE-2021-0298

Junos OS Evolved: PTX10003, PTX10008: picd core while executing the "show chassis pic" command under certain conditions

Severity Score

4.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS) condition. Continued execution of the CLI command, under precise conditions, could create a sustained Denial of Service (DoS) condition. This issue affects all Juniper Networks Junos OS Evolved versions prior to 20.1R2-EVO on PTX10003 and PTX10008 platforms. Junos OS is not affected by this vulnerability.

Una condición de carrera en el comando "show chassis pic" en Juniper Networks Junos OS Evolved puede permitir a un atacante bloquear el proceso del demonio concentrador de interfaz de puertos (picd) en el FPC, si el comando se ejecuta coincidiendo con otros eventos del sistema fuera del control del atacante, conllevando a una condición de Denegación de Servicio (DoS). La ejecución continuada del comando CLI, en condiciones precisas, podría crear una condición de Denegación de Servicio (DoS) sostenida. Este problema afecta a todas las versiones de Junos OS Evolved anteriores a 20.1R2-EVO de Juniper Networks en las plataformas PTX10003 y PTX10008. Junos OS no está afectado por esta vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Local
Attack Complexity
High
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-10-27 CVE Reserved
  • 2021-10-19 CVE Published
  • 2023-05-12 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://kb.juniper.net/JSA11212 2021-10-25
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
18.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "18.3"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
18.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "18.3"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.1"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.1"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.1"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.1"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.2
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.2"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.2
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.2"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.2
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.2"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.2
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.2"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.3"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.3"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.3"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.3
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.3"
r2
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.4
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.4"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.4
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.4"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.4
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.4"
r1-s1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
19.4
Search vendor "Juniper" for product "Junos Os Evolved" and version "19.4"
r1-s1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
20.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "20.1"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
20.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "20.1"
r1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
20.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "20.1"
r1-s1
Affected
in Juniper
Search vendor "Juniper"
Ptx10003
Search vendor "Juniper" for product "Ptx10003"
--
Safe
Juniper
Search vendor "Juniper"
Junos Os Evolved
Search vendor "Juniper" for product "Junos Os Evolved"
20.1
Search vendor "Juniper" for product "Junos Os Evolved" and version "20.1"
r1-s1
Affected
in Juniper
Search vendor "Juniper"
Ptx10008
Search vendor "Juniper" for product "Ptx10008"
--
Safe