First published: Fri Jul 17 2020(Updated: )
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue occurs only when the device is receiving and processing the BGP UPDATE for an EBGP peer. This issue does not occur when the device is receiving and processing the BGP UPDATE for an IBGP peer. However, the offending BGP UPDATE can originally come from an EBGP peer, propagates through the network via IBGP peers without causing crash, then it causes RPD crash when it is processed for a BGP UPDATE towards an EBGP peer. Repeated receipt and processing of the same specific BGP UPDATE can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 17.3R3-S6, 17.4R2-S7, and 18.1R3-S7. Juniper Networks Junos OS Evolved 19.2R2-EVO and later versions, prior to 19.3R1-EVO. Other Junos OS releases are not affected.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | =17.3-r3-s6 | |
Juniper Junos | =17.4-r2-s7 | |
Juniper Junos | =18.1-r3-s7 | |
Juniper Networks Junos OS | =19.2-r2 |
The following software releases have been updated to resolve this specific issue: Junos OS: 17.3R3-S7, 17.4R2-S8, 18.1R3-S8, and all subsequent releases. This fix has been proactively committed to other Junos OS releases that are not vulnerable to this issue. Junos OS Evolved: 19.3R1-EVO and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-1646 is classified as high, as it can cause significant impact due to the routing process daemon crashing.
To fix CVE-2020-1646, upgrade to the fixed versions of Junos OS and Junos OS Evolved specified in the vendor's security advisory.
CVE-2020-1646 affects Juniper Networks Junos OS and Junos OS Evolved devices running specific versions as outlined in the vulnerability description.
CVE-2020-1646 is a denial-of-service vulnerability that can lead to crashes in the routing process daemon.
CVE-2020-1646 was disclosed in June 2020 as part of Juniper's ongoing commitment to security.