Security readout for executives and security teams
Plain-English summary
Certain Juniper ACX5448 and ACX710 routers running affected Junos OS releases can lose BFD stability when receiving high-rate transit ARP traffic. BFD flaps can disrupt routing adjacencies and cause network instability or denial of service. The issue is availability-focused; sources do not indicate data exposure or code execution.
Executive priority
Treat this as a moderate network availability risk. It is not a confidentiality or integrity issue, but affected edge or aggregation routers could destabilize routing under specific ARP traffic conditions. Remediate during planned network maintenance, faster for critical paths.
Technical view
High-rate transit ARP packets may be exceptioned to CPU, causing BFD detect timer expiry and BFD down/up events. Routing protocols relying on BFD, including IS-IS in the sample logs, may lose adjacency. CVSS 3.1 is 6.5, AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Likely exposure
Exposure appears limited to Junos OS on ACX5448 and ACX710 platforms only. The source lists vulnerable Junos OS trains 18.2 through 20.2 before specified fixed releases. No other Juniper products or platforms are identified as affected in the provided source bundle.
Exploitation context
The source bundle and KEV status do not show known active exploitation. The attack vector is adjacent network, so practical risk is highest where untrusted or unstable Layer 2 environments can deliver high-rate transit ARP traffic to affected routers.
Researcher notes
The evidence is specific and vendor-scoped: ACX5448 and ACX710 only. Validation should focus on platform, Junos train, BFD flapping, CPU-exceptioned transit ARP, and dependent routing protocols. Do not generalize impact to other Juniper platforms without new source evidence.
Mitigation direction
- Inventory ACX5448 and ACX710 routers and record Junos OS release trains.
- Upgrade affected devices to the fixed Junos OS releases listed by Juniper or later.
- Prioritize routers supporting critical routing adjacencies or high-availability paths.
- Monitor Juniper guidance for any additional workarounds or operational recommendations.
Validation and detection
- Confirm device platform is ACX5448 or ACX710 before treating it as affected.
- Compare installed Junos OS versions against the affected and fixed release list.
- Review logs for BFDD_STATE_UP_TO_DOWN, BFDD_TRAP_SHOP_STATE_DOWN, and routing adjacency loss messages.
- Check whether BFD flaps correlate with high rates of transit ARP traffic.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-0216 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.juniper.net/JSA11118CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
