A critical remote code-execution vulnerability in Juniper Networks Steel-Belted Radius (SBR) Carrier Edition lays open wireless carrier and fixed operator networks to tampering. The bug (CVE-2021-0276) affects SBR Carrier versions 8.4.1, 8.5.0 and 8.6.0 that use extensible authentication protocol. An attacker can exploit by sending specially crafted packets to the platform, causing RADIUS to crash. This can result in RCE, and also denial-of-service (DoS) that would prevent phone subscribers from having a network connection.
Source: https://threatpost.com/critical-juniper-bug-dos-rce-carrier/167869/

