LiveActive security incident?Get immediate response
CVE Record

CVE-2021-0251: Junos OS: MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC: The BRAS Subscriber Services service activation portal is vulnerable to a Denial of Service (DoS) via malformed HTTP packets

A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC or MS-MPC allows an attacker to send malformed HTTP packets to the device thereby causing a Denial of Service (DoS), crashing the Multiservices PIC Management Daemon (mspmand) process thereby denying users the ability to login, while concurrently impacting other mspmand services and traffic through the device. Continued receipt and processing of these malformed packets will create a sustained Denial of Service (DoS) condition. While the Services PIC is restarting, all PIC services will be bypassed until the Services PIC completes its boot process. An attacker sending these malformed HTTP packets to the device who is not part of the Captive Portal experience is not able to exploit this issue. This issue is not applicable to MX RE-based CPCD platforms. This issue affects: Juniper Networks Junos OS on MX Series 17.3 version 17.3R1 and later versions prior to 17.4 versions 17.4R2-S9, 17.4R3-S2; 18.1 versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R3-S1; 18.4 versions prior to 18.4R3; 19.1 versions prior to 19.1R2-S2, 19.1R3; 19.2 versions prior to 19.2R2; 19.3 versions prior to 19.3R3. This issue does not affect: Juniper Networks Junos OS versions prior to 17.3R1.

HighCVSS 8.6Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Certain Juniper MX routers can be knocked into a denial-of-service state through malformed HTTP traffic aimed at the subscriber service activation portal. The result can block user logins and affect other services using the multiservices process. The issue is high severity, but the source says attackers outside the Captive Portal experience cannot exploit it.

Executive priority

Treat as high priority for service-provider or enterprise MX environments that rely on subscriber portal services. The main business risk is availability disruption, failed user logins, and bypassed PIC services during restart cycles.

Technical view

CVE-2021-0251 is a NULL pointer dereference in Junos OS CPCD on MX Series with MS-PIC, MS-SPC3, MS-MIC, or MS-MPC. Malformed HTTP packets can crash mspmand, denying subscriber login and impacting related traffic. Repeated packets can sustain DoS; while the Services PIC restarts, PIC services are bypassed.

Likely exposure

Exposure is limited to Junos OS MX Series deployments using MS-PIC, MS-SPC3, MS-MIC, or MS-MPC with the BRAS Subscriber Services activation portal/CPCD path. MX RE-based CPCD platforms and Junos OS versions before 17.3R1 are stated as not affected.

Exploitation context

The bundle does not report active exploitation, and KEV is false. Exploitation is network reachable with low complexity and no privileges per CVSS, but Juniper states an attacker outside the Captive Portal experience cannot exploit this issue.

Researcher notes

The vulnerability is CWE-476 with CVSS 3.1 score 8.6. Affected ranges begin at Junos OS 17.3R1 and span 17.4 through 19.3 before specified fixed releases. Evidence is vendor-centered; the bundle provides no public exploit confirmation.

Mitigation direction

  • Upgrade affected Junos OS trains to Juniper-listed fixed releases or later.
  • Prioritize MX subscriber-services environments where captive portal availability affects customer access.
  • Confirm whether deployed platforms use MS-PIC, MS-SPC3, MS-MIC, or MS-MPC.
  • Check Juniper JSA11144 for supported workaround or operational mitigation guidance.
  • Monitor for repeated mspmand or Services PIC restarts until remediation is complete.

Validation and detection

  • Inventory MX Series routers and record Junos OS versions and services modules.
  • Determine whether BRAS Subscriber Services activation portal or CPCD is in use.
  • Compare versions against the affected and fixed ranges in Juniper JSA11144.
  • Review logs for cpcd, mspmand, or Services PIC crash and restart patterns.
  • Validate that MX RE-based CPCD platforms are not incorrectly included as affected.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-476: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-0251 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H3.94Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

8.6High
CVSS 3.1 vector shape for CVE-2021-0251Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Juniper NetworksJunos OSunspecified, 17.3R1, 17.4, 18.1, 18.2, 18.3, 18.4, 19.1, 19.2, 19.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-476 · source CWE mapping

NULL Pointer Dereference

NULL Pointer Dereference represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.