CVE-2020-1637: Junos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability

Published Apr 8, 2020
·
Updated

A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Controller (IC) is configured as an IP address range instead of an IP address/netmask. See the Workaround section for more detail. The Junos OS Enforcer CLI settings are disabled by default. This issue affects Juniper Networks Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D100; 15.1X49 versions prior to 15.1X49-D210; 17.3 versions prior to 17.3R2-S5, 17.3R3-S8; 17.4 versions prior to 17.4R2-S9, 17.4R3-S1; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R3-S2; 18.4 versions prior to 18.4R1-S6, 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R1-S4, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S3, 19.2R2; 19.3 versions prior to 19.3R2-S1, 19.3R3; 19.4 versions prior to 19.4R1-S1, 19.4R2.

Affected Software

142 affected components
Juniper Junos=12.3x48
Juniper Junos=12.3x48-d10
Juniper Junos=12.3x48-d15
Juniper Junos=12.3x48-d20
Juniper Junos=12.3x48-d25
Juniper Junos=12.3x48-d30
Juniper Junos=12.3x48-d35
Juniper Junos=12.3x48-d40
Juniper Junos=12.3x48-d45
Juniper Junos=12.3x48-d50
Juniper Junos=12.3x48-d51
Juniper Junos=12.3x48-d55
Juniper Junos=12.3x48-d60
Juniper Junos=12.3x48-d65
Juniper Junos=12.3x48-d70
Juniper Junos=12.3x48-d75
Juniper Junos=12.3x48-d80
Juniper Junos=15.1x49
Juniper Junos=15.1x49-d10
Juniper Junos=15.1x49-d100
Juniper Junos=15.1x49-d110
Juniper Junos=15.1x49-d120
Juniper Junos=15.1x49-d130
Juniper Junos=15.1x49-d140
Juniper Junos=15.1x49-d15
Juniper Junos=15.1x49-d150
Juniper Junos=15.1x49-d160
Juniper Junos=15.1x49-d170
Juniper Junos=15.1x49-d180
Juniper Junos=15.1x49-d190
Juniper Junos=15.1x49-d20
Juniper Junos=15.1x49-d200
Juniper Junos=15.1x49-d25
Juniper Junos=15.1x49-d30
Juniper Junos=15.1x49-d35
Juniper Junos=15.1x49-d40
Juniper Junos=15.1x49-d45
Juniper Junos=15.1x49-d50
Juniper Junos=15.1x49-d55
Juniper Junos=15.1x49-d60
Juniper Junos=15.1x49-d65
Juniper Junos=15.1x49-d70
Juniper Junos=15.1x49-d75
Juniper Junos=15.1x49-d80
Juniper Junos=15.1x49-d90
Juniper Junos=17.3
Juniper Junos=17.3-r1-s1
Juniper Junos=17.3-r2
Juniper Junos=17.3-r2-s1
Juniper Junos=17.3-r2-s2
Juniper Junos=17.3-r2-s3
Juniper Junos=17.3-r2-s4
Juniper Junos=17.3-r3
Juniper Junos=17.3-r3-s1
Juniper Junos=17.3-r3-s2
Juniper Junos=17.3-r3-s3
Juniper Junos=17.3-r3-s4
Juniper Junos=17.3-r3-s5
Juniper Junos=17.3-r3-s6
Juniper Junos=17.3-r3-s7
Juniper Junos=17.4
Juniper Junos=17.4-r1
Juniper Junos=17.4-r1-s1
Juniper Junos=17.4-r1-s2
Juniper Junos=17.4-r1-s4
Juniper Junos=17.4-r1-s5
Juniper Junos=17.4-r1-s6
Juniper Junos=17.4-r1-s7
Juniper Junos=17.4-r2
Juniper Junos=17.4-r2-s1
Juniper Junos=17.4-r2-s2
Juniper Junos=17.4-r2-s3
Juniper Junos=17.4-r2-s4
Juniper Junos=17.4-r2-s5
Juniper Junos=17.4-r2-s6
Juniper Junos=17.4-r2-s7
Juniper Junos=17.4-r2-s8
Juniper Junos=17.4-r3
Juniper Junos=18.1
Juniper Junos=18.1-r2
Juniper Junos=18.1-r2-s1
Juniper Junos=18.1-r2-s2
Juniper Junos=18.1-r2-s4
Juniper Junos=18.1-r3
Juniper Junos=18.1-r3-s1
Juniper Junos=18.1-r3-s2
Juniper Junos=18.1-r3-s3
Juniper Junos=18.1-r3-s4
Juniper Junos=18.1-r3-s6
Juniper Junos=18.1-r3-s7
Juniper Junos=18.1-r3-s8
Juniper Junos=18.1-r3-s9
Juniper Junos=18.2
Juniper Junos=18.2-r1
Juniper Junos=18.2-r1-s3
Juniper Junos=18.2-r1-s5
Juniper Junos=18.2-r2-s1
Juniper Junos=18.2-r2-s2
Juniper Junos=18.2-r2-s3
Juniper Junos=18.2-r2-s4
Juniper Junos=18.2-r2-s5
Juniper Junos=18.2-r2-s6
Juniper Junos=18.2-r3
Juniper Junos=18.2-r3-s1
Juniper Junos=18.2-r3-s2
Juniper Junos=18.3
Juniper Junos=18.3-r1
Juniper Junos=18.3-r1-s1
Juniper Junos=18.3-r1-s2
Juniper Junos=18.3-r1-s3
Juniper Junos=18.3-r1-s4
Juniper Junos=18.3-r1-s5
Juniper Junos=18.3-r1-s6
Juniper Junos=18.3-r2
Juniper Junos=18.3-r2-s1
Juniper Junos=18.3-r2-s2
Juniper Junos=18.3-r3
Juniper Junos=18.3-r3-s1
Juniper Junos=18.4
Juniper Junos=18.4-r1
Juniper Junos=18.4-r1-s1
Juniper Junos=18.4-r1-s2
Juniper Junos=18.4-r1-s3
Juniper Junos=18.4-r1-s4
Juniper Junos=18.4-r1-s5
Juniper Junos=18.4-r2
Juniper Junos=18.4-r2-s1
Juniper Junos=18.4-r2-s2
Juniper Junos=18.4-r2-s3
Juniper Junos=18.4-r3
Juniper Junos=19.1
Juniper Junos=19.1-r1
Juniper Junos=19.1-r1-s1
Juniper Junos=19.1-r1-s2
Juniper Junos=19.1-r1-s3
Juniper Junos=19.1-r2
Juniper Junos=19.2
Juniper Junos=19.2-r1
Juniper Junos=19.2-r1-s1
Juniper Junos=19.2-r1-s2
Juniper Junos=19.3-r2
Juniper Junos=19.4-r1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.3X48-D100
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 15.1X49-D210
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.1R7-S7
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.3R2-S5
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.3R3-S8
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.4R2-S9
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.4R3-S1
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.1R3-S10
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.2R3-S3
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.3R1-S7
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.3R3-S2
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.4R1-S6
  13. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.4R2-S4
  14. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.4R3-S1
  15. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.1R1-S4
  16. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.1R2-S1
  17. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.1R3
  18. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.2R1-S3
  19. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.2R2
  20. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.3R2-S1
  21. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.3R3
  22. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.4R1-S1
  23. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.4R2
  24. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 20.1R1
  25. Configuration

    For Junos OS Enforcer deployments that use an Infranet Controller (IC), ensure the IC IP address range is configured as an IP address/netmask (not just an IP address range), since the bypass may occur when configured as an IP address range.

    Infranet Controller (IC) IP address range = configured as an IP address/netmask instead of an IP address range

Event History

Apr 8, 2020
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2020-1637?

CVE-2020-1637 is rated as a medium severity vulnerability that can allow unauthorized access to network resources.

2

How do I fix CVE-2020-1637?

To fix CVE-2020-1637, upgrade your Juniper Networks SRX device to the patched version of Junos OS as specified by the vendor.

3

What devices are affected by CVE-2020-1637?

CVE-2020-1637 affects Juniper Networks SRX Series devices configured as Junos OS Enforcer devices.

4

What could happen if CVE-2020-1637 is exploited?

If exploited, CVE-2020-1637 could allow an attacker to gain access to network resources that are not permitted by the User Access Control policy.

5

When was CVE-2020-1637 disclosed?

CVE-2020-1637 was publicly disclosed as part of Juniper's security advisories and is linked to JSA11018.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203