Juniper Networks Junos OSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-0254£©
°ä²¼¹¦·ò 2021-04-190x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-0254 | ʱ ¼ä | 2021-04-19 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê04ÔÂ14ÈÕ£¬Juniper°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËJuniper Networks Junos OSÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-0254£©£¬¸Ã·ì϶µÄCVSSv3µÃ·ÖΪ9.8¡£
¸Ã·ì϶ÊÇJunos OSµÄoverlayd·þÎñÖеĻº³åÇø´óÓ×ÑéÖ¤²»ÕýÈ·µ¼Öµģ¬OverlaydÊØ»¤¹ý³ÌÕÆ¹Ü´¦Ö÷¢Ë͵½overlaydµÄOAMÊý¾Ý°ü£¬ÈçpingºÍtraceroute¡£¸Ã·þÎñĬÈÏÒÔrootÉí·ÝÔËÐУ¬ÔÚ4789¶Ë¿Ú¼àÌýUDPÏνӡ£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìÉ豸·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢´Ë·ì϶£¬ÒÔµ¼Ö»ؾø·þÎñ£¨DoS£©»òÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£
´Ë±í£¬overlaydĬÈÏÔÚMXϵÁÓ×¢ACXϵÁкÍQFXϵÁÐÆ½Ì¨ÉÏÔËÐС£ÈôÊÇÅäÖÃÁËÐé¹¹¿ÉÀ©´ó¾ÖÓòÍø£¨VXLAN£©overlay network£¬ÔòÆäËüƽ̨Ҳ´æÔÚ´Ë·ì϶¡£
Ó°ÏìÁìÓò
Juniper Networks Junos OS 15.1X49¡¢15.1¡¢17.3¡¢17.4¡¢18.1¡¢18.2¡¢18.3¡¢18.4¡¢19.1¡¢19.2¡¢19.3¡¢19.4¡¢20.1¡¢20.2¡¢20.3¡£
0x02 ´ëÖý¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º
Junos OS 15.1X49-D240¡¢15.1R7-S9¡¢17.3R3-S11¡¢17.4R2-S13¡¢17.4R3-S4¡¢18.1R3-S12¡¢18.2R2-S8¡¢18.2R3-S7¡¢18.3R3-S4¡¢18.4R1-S8¡¢18.4R2-S7¡¢18.4R3-S7¡¢19.1R2-S2¡¢19.1R3-S4¡¢19.2R1-S6¡¢19.2R3-S2¡¢19.3R3-S1¡¢19.4R2-S4¡¢1R3-S4¡¢19.2R1-S6¡¢19.2R3-S2¡¢19.3R3-S1¡¢19.4R2-S4¡¢19.4R3-S1¡¢20.1R2-S1¡¢20.1R3¡¢20.2R2¡¢20.2R2-S1¡¢20.2R3¡¢20.3R1-S1¡¢20.4R1¼°ºóÐø¿¯Ðа汾¡£
ÏÂÔØÁ´½Ó£º
https://support.juniper.net/support/downloads/
0x03 ²Î¿¼Á´½Ó
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11147
https://securityaffairs.co/wordpress/116907/security/juniper-networks-rce.html?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0254
0x04 ¹¦·òÏß
2021-04-14 Juniper°ä²¼°²È«²¼¸æ
2021-04-19 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ