First published: Wed Jul 08 2020(Updated: )
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =18.2x75 | |
Juniper JUNOS | =18.2x75 | |
Juniper JUNOS | =18.2x75-d20 | |
Juniper JUNOS | =18.2x75-d30 | |
Juniper JUNOS | =18.2x75-d40 | |
Juniper JUNOS | =19.4-r1 | |
Juniper JUNOS | =19.4-r1-s1 | |
Juniper JUNOS | =20.1-r1 | |
Juniper JUNOS | =20.1-r1-s1 | |
Juniper Networks Junos OS Evolved | =19.4-r1 | |
Juniper Networks Junos OS Evolved | =19.4-r2 | |
Juniper Networks Junos OS Evolved | =19.4-r2-s1 | |
Juniper Networks Junos OS Evolved | =20.1-r1 |
The following software releases have been updated to resolve this specific issue: Junos OS: 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70, 19.4R1-S2, 19.4R2, 20.1R1-S2, 20.1R2, 20.2R1, and all subsequent releases. Junos OS Evolved: 19.4R2-S2-EVO, 20.1R2-EVO, 20.2R1-EVO and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1648 has been assigned a high severity rating due to its potential to cause a crash in routing processes.
To mitigate CVE-2020-1648, it is recommended to apply the appropriate software patches or updates provided by Juniper Networks.
CVE-2020-1648 affects specific versions of Juniper Networks Junos OS and Junos OS Evolved devices.
CVE-2020-1648 can lead to a routing process daemon crash, which disrupts network operations requiring routing.
Currently, there are no documented workarounds for CVE-2020-1648 aside from patching the affected systems.