LiveActive security incident?Get immediate response
CVE Record

CVE-2021-0216: Junos OS: ACX5448, ACX710: BFD sessions might flap due to high rate of transit ARP packets

A vulnerability in Juniper Networks Junos OS running on the ACX5448 and ACX710 platforms may cause BFD sessions to flap when a high rate of transit ARP packets are received. This, in turn, may impact routing protocols and network stability, leading to a Denial of Service (DoS) condition. When a high rate of transit ARP packets are exceptioned to the CPU and BFD flaps, the following log messages may be seen: bfdd[15864]: BFDD_STATE_UP_TO_DOWN: BFD Session 192.168.14.3 (IFL 232) state Up -> Down LD/RD(17/19) Up time:11:38:17 Local diag: CtlExpire Remote diag: None Reason: Detect Timer Expiry. bfdd[15864]: BFDD_TRAP_SHOP_STATE_DOWN: local discriminator: 17, new state: down, interface: irb.998, peer addr: 192.168.14.3 rpd[15839]: RPD_ISIS_ADJDOWN: IS-IS lost L2 adjacency to peer on irb.998, reason: BFD Session Down bfdd[15864]: BFDD_TRAP_SHOP_STATE_UP: local discriminator: 17, new state: up, interface: irb.998, peer addr: 192.168.14.3 This issue only affects the ACX5448 Series and ACX710 Series routers. No other products or platforms are affected by this vulnerability. This issue affects Juniper Networks Junos OS: 18.2 versions prior to 18.2R3-S8 on ACX5448; 18.3 versions prior to 18.3R3-S5 on ACX5448; 18.4 versions prior to 18.4R1-S6, 18.4R3-S7 on ACX5448; 19.1 versions prior to 19.1R3-S5 on ACX5448; 19.2 versions prior to 19.2R2, 19.2R3 on ACX5448; 19.3 versions prior to 19.3R3 on ACX5448; 19.4 versions prior to 19.4R3 on ACX5448; 20.1 versions prior to 20.1R2 on ACX5448; 20.2 versions prior to 20.2R2 on ACX5448 and ACX710.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Certain Juniper ACX5448 and ACX710 routers running affected Junos OS releases can lose BFD stability when receiving high-rate transit ARP traffic. BFD flaps can disrupt routing adjacencies and cause network instability or denial of service. The issue is availability-focused; sources do not indicate data exposure or code execution.

Executive priority

Treat this as a moderate network availability risk. It is not a confidentiality or integrity issue, but affected edge or aggregation routers could destabilize routing under specific ARP traffic conditions. Remediate during planned network maintenance, faster for critical paths.

Technical view

High-rate transit ARP packets may be exceptioned to CPU, causing BFD detect timer expiry and BFD down/up events. Routing protocols relying on BFD, including IS-IS in the sample logs, may lose adjacency. CVSS 3.1 is 6.5, AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Likely exposure

Exposure appears limited to Junos OS on ACX5448 and ACX710 platforms only. The source lists vulnerable Junos OS trains 18.2 through 20.2 before specified fixed releases. No other Juniper products or platforms are identified as affected in the provided source bundle.

Exploitation context

The source bundle and KEV status do not show known active exploitation. The attack vector is adjacent network, so practical risk is highest where untrusted or unstable Layer 2 environments can deliver high-rate transit ARP traffic to affected routers.

Researcher notes

The evidence is specific and vendor-scoped: ACX5448 and ACX710 only. Validation should focus on platform, Junos train, BFD flapping, CPU-exceptioned transit ARP, and dependent routing protocols. Do not generalize impact to other Juniper platforms without new source evidence.

Mitigation direction

  • Inventory ACX5448 and ACX710 routers and record Junos OS release trains.
  • Upgrade affected devices to the fixed Junos OS releases listed by Juniper or later.
  • Prioritize routers supporting critical routing adjacencies or high-availability paths.
  • Monitor Juniper guidance for any additional workarounds or operational recommendations.

Validation and detection

  • Confirm device platform is ACX5448 or ACX710 before treating it as affected.
  • Compare installed Junos OS versions against the affected and fixed release list.
  • Review logs for BFDD_STATE_UP_TO_DOWN, BFDD_TRAP_SHOP_STATE_DOWN, and routing adjacency loss messages.
  • Check whether BFD flaps correlate with high rates of transit ARP traffic.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-0216 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.1MediumCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.5Medium
CVSS 3.1 vector shape for CVE-2021-0216Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Juniper NetworksJunos OS18.2, 18.3, 18.4, 19.1, 19.2, 19.3, 19.4, 20.1Listed
Juniper NetworksJunos OS20.2Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.