PT-2020-5152 · Juniper Networks · Junos

Published

2020-10-14

·

Updated

2020-10-28

·

CVE-2020-1683

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Junos versions 17.4R3 through 19.4R1-S3
Description The issue is related to a memory leak caused by a specific SNMP OID poll, which can lead to a kernel crash over time. This may also impact other processes, such as establishing SSH connections to the device. The administrator can monitor the system virtual memory to check for memory leaks.
Recommendations For Junos versions 17.4R3 through 19.4R1-S3, update to a version that is not affected by this issue, such as 18.1R3-S10, 18.2R3-S3, 18.2X75-D430, 18.2X75-D53, 18.2X75-D60, 18.3R3-S2, 18.4R2-S5, 18.4R3-S1, 19.1R2-S2, 19.1R3, 19.2R1-S5, 19.2R2, 19.3R2-S5, 19.3R3, or 19.4R2. As a temporary workaround, consider monitoring the system virtual memory to detect potential memory leaks caused by this issue.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05758
CVE-2020-1683

Affected Products

Junos