CVE-2020-1628: Junos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration information such as heartbeats, kernel versions, etc. out to the Internet, leading to an information exposure vulnerability. This issue affects Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D53 on EX4300; 15.1 versions prior to 15.1R7-S6 on EX4300; 15.1X49 versions prior to 15.1X49-D200, 15.1X49-D210 on EX4300; 16.1 versions prior to 16.1R7-S7 on EX4300; 17.1 versions prior to 17.1R2-S11, 17.1R3-S2 on EX4300; 17.2 versions prior to 17.2R3-S3 on EX4300; 17.3 versions prior to 17.3R2-S5, 17.3R3-S7 on EX4300; 17.4 versions prior to 17.4R2-S9, 17.4R3 on EX4300; 18.1 versions prior to 18.1R3-S8 on EX4300; 18.2 versions prior to 18.2R3-S2 on EX4300; 18.3 versions prior to 18.3R2-S3, 18.3R3, 18.3R3-S1 on EX4300; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3 on EX4300; 19.1 versions prior to 19.1R1-S4, 19.1R2 on EX4300; 19.2 versions prior to 19.2R1-S4, 19.2R2 on EX4300; 19.3 versions prior to 19.3R1-S1, 19.3R2 on EX4300.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 14.1X53-D53 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 15.1R7-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 15.1X49-D200 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 15.1X49-D210 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 16.1R7-S7 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.1R2-S11 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.1R3-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.2R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.3R2-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.3R3-S7 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.4R2-S9 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 17.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.1R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.2R3-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.3R2-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.3R3-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.4R1-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.4R2-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 18.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.1R1-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.1R2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.2R1-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.2R2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.3R1-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4300)to a version that resolves this vulnerability.Fixed in 19.3R2
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1628?
The severity of CVE-2020-1628 is classified as high due to the potential leakage of sensitive configuration information.
How do I fix CVE-2020-1628?
To fix CVE-2020-1628, update to a patched version of Junos OS as specified in the vendor's advisory.
What versions of Junos OS are affected by CVE-2020-1628?
CVE-2020-1628 affects multiple versions including 14.1x53, 15.1, 16.1, 17.1, 17.2, 17.3, and 18.1.
What happens if my device is vulnerable to CVE-2020-1628?
If your device is vulnerable to CVE-2020-1628, there is a risk of leaking configuration information over unsecured networks.
Is there a workaround for CVE-2020-1628?
Currently, there is no effective workaround for CVE-2020-1628 apart from applying the recommended software update.