PT-2020-1513 · Juniper Networks · Junos

Published

2020-01-08

·

Updated

2021-09-14

·

CVE-2020-1600

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions 12.3X48 prior to 12.3X48-D90 Juniper Networks Junos OS versions 15.1 prior to 15.1R7-S6 Juniper Networks Junos OS versions 15.1X49 prior to 15.1X49-D200 Juniper Networks Junos OS versions 15.1X53 prior to 15.1X53-D238, 15.1X53-D592 Juniper Networks Junos OS versions 16.1 prior to 16.1R7-S5 Juniper Networks Junos OS versions 16.2 prior to 16.2R2-S11 Juniper Networks Junos OS versions 17.1 prior to 17.1R3-S1 Juniper Networks Junos OS versions 17.2 prior to 17.2R3-S2 Juniper Networks Junos OS versions 17.3 prior to 17.3R3-S7 Juniper Networks Junos OS versions 17.4 prior to 17.4R2-S4, 17.4R3 Juniper Networks Junos OS versions 18.1 prior to 18.1R3-S5 Juniper Networks Junos OS versions 18.2 prior to 18.2R3 Juniper Networks Junos OS versions 18.2X75 prior to 18.2X75-D50 Juniper Networks Junos OS versions 18.3 prior to 18.3R2 Juniper Networks Junos OS versions 18.4 prior to 18.4R2 Juniper Networks Junos OS versions 19.1 prior to 19.1R2
Description The issue is related to an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS. This vulnerability can be triggered by a specific SNMP request, causing an infinite loop and resulting in a high CPU usage Denial of Service (DoS) condition. The issue affects both SNMP over IPv4 and IPv6.
Recommendations As a temporary workaround, consider disabling the SNMP service until a patch is available. Restrict access to the vulnerable Routing Protocol Daemon (RPD) to minimize the risk of exploitation. Update to a fixed version of Juniper Networks Junos OS for each affected version. For versions 12.3X48, update to 12.3X48-D90 or later. For versions 15.1, update to 15.1R7-S6 or later. For versions 15.1X49, update to 15.1X49-D200 or later. For versions 15.1X53, update to 15.1X53-D238, 15.1X53-D592 or later. For versions 16.1, update to 16.1R7-S5 or later. For versions 16.2, update to 16.2R2-S11 or later. For versions 17.1, update to 17.1R3-S1 or later. For versions 17.2, update to 17.2R3-S2 or later. For versions 17.3, update to 17.3R3-S7 or later. For versions 17.4, update to 17.4R2-S4, 17.4R3 or later. For versions 18.1, update to 18.1R3-S5 or later. For versions 18.2, update to 18.2R3 or later. For versions 18.2X75, update to 18.2X75-D50 or later. For versions 18.3, update to 18.3R2 or later. For versions 18.4, update to 18.4R2 or later. For versions 19.1, update to 19.1R2 or later.

Fix

DoS

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00496
CVE-2020-1600

Affected Products

Junos