A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the radius daemon, causing a sustained Denial of Service (DoS). This issue affects Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R19; 8.5.0 versions prior to 8.5.0R10; 8.6.0 versions prior to 8.6.0R4.

Published at
2021-07-15
185 days ago
Modified
2021-07-15
185 days ago
2021
Year
The year of the turtle

https://kb.juniper.net/JSA11180

CONFIRM:https://kb.juniper.net/JSA11180

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2021-0276"
	},
	"Notes": {
		"Note": [
			{
				"_text": "A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the radius daemon, causing a sustained Denial of Service (DoS). This issue affects Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R19; 8.5.0 versions prior to 8.5.0R10; 8.6.0 versions prior to 8.6.0R4."
			},
			{
				"_text": "2021-07-15"
			},
			{
				"_text": "2021-07-15"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2021-0276"
	},
	"References": {
		"Reference": {
			"URL": {
				"_text": "https://kb.juniper.net/JSA11180"
			},
			"Description": {
				"_text": "CONFIRM:https://kb.juniper.net/JSA11180"
			}
		}
	}
}