PT-2020-4139 · Juniper Networks · Junos
Published
2020-04-08
·
Updated
2021-11-22
·
CVE-2020-1633
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Junos OS versions 17.4 through 19.2R2
Description:
A crafted NDPv6 packet could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, leading to a Denial of Service (DoS) condition. The issue only affects IPv6, and IPv4 ARP proxy is unaffected.
Recommendations:
For Junos OS 17.4 versions prior to 17.4R2-S9, 17.4R3 on MX Series, update to 17.4R2-S9 or later.
For Junos OS 18.1 versions prior to 18.1R3-S9 on MX Series, update to 18.1R3-S9 or later.
For Junos OS 18.2 versions prior to 18.2R2-S7, 18.2R3-S3 on MX Series, update to 18.2R2-S7 or later.
For Junos OS 18.2X75 versions prior to 18.2X75-D33, 18.2X75-D411, 18.2X75-D420, 18.2X75-D60 on MX Series, update to 18.2X75-D33 or later.
For Junos OS 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3 on MX Series, update to 18.3R1-S7 or later.
For Junos OS 18.4 versions prior to 18.4R1-S5, 18.4R2-S2, 18.4R3 on MX Series, update to 18.4R1-S5 or later.
For Junos OS 19.1 versions prior to 19.1R1-S4, 19.1R2 on MX Series, update to 19.1R1-S4 or later.
For Junos OS 19.2 versions prior to 19.2R1-S3, 19.2R2 on MX Series, update to 19.2R1-S3 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos