PT-2020-5149 · Juniper Networks · Junos

Published

2020-10-14

·

Updated

2021-02-05

·

CVE-2020-1671

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions prior to 17.4R2-S12 Juniper Networks Junos OS versions prior to 17.4R3-S3 Juniper Networks Junos OS versions prior to 18.1R3-S11 Juniper Networks Junos OS versions prior to 18.2R3-S6 Juniper Networks Junos OS versions prior to 18.2X75-D65 Juniper Networks Junos OS versions prior to 18.3R2-S4 Juniper Networks Junos OS versions prior to 18.3R3-S3 Juniper Networks Junos OS versions prior to 18.4R2-S5 Juniper Networks Junos OS versions prior to 18.4R3-S4 Juniper Networks Junos OS versions prior to 19.1R3-S2 Juniper Networks Junos OS versions prior to 19.2R1-S5 Juniper Networks Junos OS versions prior to 19.2R3 Juniper Networks Junos OS version 19.2R2 Juniper Networks Junos OS versions prior to 19.3R2-S4 Juniper Networks Junos OS versions prior to 19.3R3 Juniper Networks Junos OS versions prior to 19.4R1-S3 Juniper Networks Junos OS versions prior to 19.4R2-S2 Juniper Networks Junos OS versions prior to 19.4R3 Juniper Networks Junos OS versions prior to 20.1R1-S3 Juniper Networks Junos OS versions prior to 20.1R2
Description The issue affects Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent. A malformed DHCPv6 packet can cause the Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process to crash with a core dump, resulting in the restart of the daemon. This issue only affects DHCPv6 and does not affect DHCPv4. The exploitation of this issue may allow a remote attacker to cause a core dump in response to a malformed DHCPv6 packet.
Recommendations For Juniper Networks Junos OS versions prior to 17.4R2-S12, update to version 17.4R2-S12 or later. For Juniper Networks Junos OS versions prior to 17.4R3-S3, update to version 17.4R3-S3 or later. For Juniper Networks Junos OS versions prior to 18.1R3-S11, update to version 18.1R3-S11 or later. For Juniper Networks Junos OS versions prior to 18.2R3-S6, update to version 18.2R3-S6 or later. For Juniper Networks Junos OS versions prior to 18.2X75-D65, update to version 18.2X75-D65 or later. For Juniper Networks Junos OS versions prior to 18.3R2-S4, update to version 18.3R2-S4 or later. For Juniper Networks Junos OS versions prior to 18.3R3-S3, update to version 18.3R3-S3 or later. For Juniper Networks Junos OS versions prior to 18.4R2-S5, update to version 18.4R2-S5 or later. For Juniper Networks Junos OS versions prior to 18.4R3-S4, update to version 18.4R3-S4 or later. For Juniper Networks Junos OS versions prior to 19.1R3-S2, update to version 19.1R3-S2 or later. For Juniper Networks Junos OS versions prior to 19.2R1-S5, update to version 19.2R1-S5 or later. For Juniper Networks Junos OS versions prior to 19.2R3, update to version 19.2R3 or later. For Juniper Networks Junos OS version 19.2R2, update to a later version. For Juniper Networks Junos OS versions prior to 19.3R2-S4, update to version 19.3R2-S4 or later. For Juniper Networks Junos OS versions prior to 19.3R3, update to version 19.3R3 or later. For Juniper Networks Junos OS versions prior to 19.4R1-S3, update to version 19.4R1-S3 or later. For Juniper Networks Junos OS versions prior to 19.4R2-S2, update to version 19.4R2-S2 or later. For Juniper Networks Junos OS versions prior to 19.4R3, update to version 19.4R3 or later. For Juniper Networks Junos OS versions prior to 20.1R1-S3, update to version 20.1R1-S3 or later. For Juniper Networks Junos OS versions prior to 20.1R2, update to version 20.1R2 or later.

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05755
CVE-2020-1671

Affected Products

Junos