CVE-2020-1637: Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Controller (IC) is configured as an IP address range instead of an IP address/netmask. See the Workaround section for more detail. The Junos OS Enforcer CLI settings are disabled by default. This issue affects Juniper Networks Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D100; 15.1X49 versions prior to 15.1X49-D210; 17.3 versions prior to 17.3R2-S5, 17.3R3-S8; 17.4 versions prior to 17.4R2-S9, 17.4R3-S1; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R3-S2; 18.4 versions prior to 18.4R1-S6, 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R1-S4, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S3, 19.2R2; 19.3 versions prior to 19.3R2-S1, 19.3R3; 19.4 versions prior to 19.4R1-S1, 19.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.3X48-D100 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1X49-D210 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1R7-S7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.3R2-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.3R3-S8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4R2-S9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4R3-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.1R3-S10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.2R3-S3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3R1-S7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3R3-S2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4R1-S6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4R2-S4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4R3-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1R1-S4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1R2-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1R3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2R1-S3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2R2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.3R2-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.3R3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.4R1-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.4R2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20.1R1 - Configuration
For Junos OS Enforcer deployments that use an Infranet Controller (IC), ensure the IC IP address range is configured as an IP address/netmask (not just an IP address range), since the bypass may occur when configured as an IP address range.
Infranet Controller (IC) IP address range = configured as an IP address/netmask instead of an IP address range
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1637?
CVE-2020-1637 is rated as a medium severity vulnerability that can allow unauthorized access to network resources.
How do I fix CVE-2020-1637?
To fix CVE-2020-1637, upgrade your Juniper Networks SRX device to the patched version of Junos OS as specified by the vendor.
What devices are affected by CVE-2020-1637?
CVE-2020-1637 affects Juniper Networks SRX Series devices configured as Junos OS Enforcer devices.
What could happen if CVE-2020-1637 is exploited?
If exploited, CVE-2020-1637 could allow an attacker to gain access to network resources that are not permitted by the User Access Control policy.
When was CVE-2020-1637 disclosed?
CVE-2020-1637 was publicly disclosed as part of Juniper's security advisories and is linked to JSA11018.