Security readout for executives and security teams
Plain-English summary
This flaw can crash the authentication service on certain Juniper MX routers when they run subscriber-management or BBE configurations. The business impact is service disruption: affected devices may lose AAA functionality, and repeated login attempts can sustain a denial-of-service condition.
Executive priority
Treat this as a moderate-priority availability risk for service-provider or broadband-edge environments. It is not evidenced as actively exploited here, but affected MX devices supporting AAA can suffer customer-facing disruption if left unpatched.
Technical view
CVE-2021-31366 is a CWE-252 unchecked-return-value issue in Junos OS authd on MX Series with subscriber management/BBE enabled. An adjacent unauthenticated attacker can trigger an authd crash via a specific subscriber username during PPP login, affecting AAA availability. CVSS is 6.5, availability impact high.
Likely exposure
Exposure is limited to Juniper MX Series running affected Junos OS versions and configured for subscriber management or BBE. Internet-wide exposure is not implied by the source bundle because the attack vector is adjacent network, not remote network.
Exploitation context
The bundle does not show CISA KEV listing or active exploitation evidence. The issue requires adjacency and a vulnerable operational configuration, but no credentials or user interaction. Repeated triggering can sustain the denial of service.
Researcher notes
Key constraints are platform, configuration, and adjacency. The sources identify Junos OS MX Series subscriber management/BBE only. Do not generalize to all Juniper products or all Junos deployments without separate evidence.
Mitigation direction
- Upgrade affected Junos OS trains to the fixed versions listed by Juniper.
- Review Juniper advisory JSA11228 before selecting a target maintenance release.
- Prioritize devices providing subscriber management, broadband edge, or AAA-dependent services.
- No source-bundle workaround is identified; follow vendor guidance for alternatives.
- Monitor authd stability and AAA availability until remediation is complete.
Validation and detection
- Inventory Juniper MX devices and record Junos OS release versions.
- Confirm whether subscriber management or BBE configuration is enabled.
- Map installed releases against Juniper's affected-version list.
- Review logs and monitoring for authd crashes or AAA interruptions.
- Verify remediated devices run a fixed or later Junos OS release.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-252: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-31366 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.juniper.net/JSA11228CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Unchecked Return Value
Unchecked Return Value represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
