CVE-2020-1648

HIGH

Juniper Junos OS and Junos OS Evolved - Denial of Service via BGP Packet Processing

Title source: llm
STIX 2.1

Description

On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://kb.juniper.net/JSA11035

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-159 CWE-690
Status published
Products (5)
juniper/junos 18.2x75 (5 CPE variants)
juniper/junos 19.4 r1 (2 CPE variants)
juniper/junos 20.1 r1 (2 CPE variants)
juniper/junos_os_evolved 19.4 r1 (3 CPE variants)
juniper/junos_os_evolved 20.1 r1
Published Jul 17, 2020
Tracked Since Feb 18, 2026