PT-2020-5930 · Juniper Networks · Junos

Published

2020-07-08

·

Updated

2021-10-19

·

CVE-2020-1651

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Juniper Networks Junos OS on MX Series versions 17.2 prior to 17.2R3-S4 Juniper Networks Junos OS on MX Series versions 17.2X75 prior to 17.2X75-D105.19 Juniper Networks Junos OS on MX Series versions 17.3 prior to 17.3R3-S7 Juniper Networks Junos OS on MX Series versions 17.4 prior to 17.4R1-S3, 17.4R2 Juniper Networks Junos OS on MX Series versions 18.1 prior to 18.1R2
Description: The issue is related to a memory leak in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series, which can be caused by receipt of a specific stream of Layer 2 frames. This can lead to a crash and restart of the PFE, resulting in traffic interruption. An attacker connected to the same broadcast domain can exploit this issue to cause a prolonged Denial of Service (DoS) by continuously sending the specific stream of Layer 2 frames.
Recommendations: For versions 17.2 prior to 17.2R3-S4, update to 17.2R3-S4 or later. For versions 17.2X75 prior to 17.2X75-D105.19, update to 17.2X75-D105.19 or later. For versions 17.3 prior to 17.3R3-S7, update to 17.3R3-S7 or later. For versions 17.4 prior to 17.4R1-S3, 17.4R2, update to 17.4R1-S3 or later, or 17.4R2 or later. For versions 18.1 prior to 18.1R2, update to 18.1R2 or later.

Fix

DoS

Memory Leak

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02045
CVE-2020-1651

Affected Products

Junos