PT-2020-4139 · Juniper Networks · Junos

Published

2020-04-08

·

Updated

2021-11-22

·

CVE-2020-1633

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions 17.4 through 19.2R2
Description: A crafted NDPv6 packet could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, leading to a Denial of Service (DoS) condition. The issue only affects IPv6, and IPv4 ARP proxy is unaffected.
Recommendations: For Junos OS 17.4 versions prior to 17.4R2-S9, 17.4R3 on MX Series, update to 17.4R2-S9 or later. For Junos OS 18.1 versions prior to 18.1R3-S9 on MX Series, update to 18.1R3-S9 or later. For Junos OS 18.2 versions prior to 18.2R2-S7, 18.2R3-S3 on MX Series, update to 18.2R2-S7 or later. For Junos OS 18.2X75 versions prior to 18.2X75-D33, 18.2X75-D411, 18.2X75-D420, 18.2X75-D60 on MX Series, update to 18.2X75-D33 or later. For Junos OS 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3 on MX Series, update to 18.3R1-S7 or later. For Junos OS 18.4 versions prior to 18.4R1-S5, 18.4R2-S2, 18.4R3 on MX Series, update to 18.4R1-S5 or later. For Junos OS 19.1 versions prior to 19.1R1-S4, 19.1R2 on MX Series, update to 19.1R1-S4 or later. For Junos OS 19.2 versions prior to 19.2R1-S3, 19.2R2 on MX Series, update to 19.2R1-S3 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04561
CVE-2020-1633

Affected Products

Junos