CVE-2020-1688: Junos OS: SRX and NFX Series: Insufficient Web API private key protection

Published Oct 16, 2020
·
Updated

On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator services. Exploitation of this vulnerability may allow an attacker to decrypt the communications between the Juniper device and the authenticator service. This Web API service is used for authentication services such as the Juniper Identity Management Service, used to obtain user identity for Integrated User Firewall feature, or the integrated ClearPass authentication and enforcement feature. This issue affects Juniper Networks Junos OS on Networks SRX Series and NFX Series: 12.3X48 versions prior to 12.3X48-D105; 15.1X49 versions prior to 15.1X49-D190; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R3; 18.3 versions prior to 18.3R2-S4, 18.3R3; 18.4 versions prior to 18.4R1-S7, 18.4R2; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S4, 19.2R2.

Affected Software

187 affected components
Juniper Junos=12.3x48
Juniper Junos=12.3x48-d10
Juniper Junos=12.3x48-d100
Juniper Junos=12.3x48-d15
Juniper Junos=12.3x48-d20
Juniper Junos=12.3x48-d25
Juniper Junos=12.3x48-d30
Juniper Junos=12.3x48-d35
Juniper Junos=12.3x48-d40
Juniper Junos=12.3x48-d45
Juniper Junos=12.3x48-d50
Juniper Junos=12.3x48-d51
Juniper Junos=12.3x48-d55
Juniper Junos=12.3x48-d60
Juniper Junos=12.3x48-d65
Juniper Junos=12.3x48-d70
Juniper Junos=12.3x48-d75
Juniper Junos=12.3x48-d80
Juniper Junos=12.3x48-d90
Juniper Junos=12.3x48-d95
Juniper Junos=15.1x49
Juniper Junos=15.1x49-d10
Juniper Junos=15.1x49-d100
Juniper Junos=15.1x49-d110
Juniper Junos=15.1x49-d120
Juniper Junos=15.1x49-d130
Juniper Junos=15.1x49-d140
Juniper Junos=15.1x49-d15
Juniper Junos=15.1x49-d150
Juniper Junos=15.1x49-d160
Juniper Junos=15.1x49-d170
Juniper Junos=15.1x49-d180
Juniper Junos=15.1x49-d20
Juniper Junos=15.1x49-d25
Juniper Junos=15.1x49-d30
Juniper Junos=15.1x49-d35
Juniper Junos=15.1x49-d40
Juniper Junos=15.1x49-d45
Juniper Junos=15.1x49-d50
Juniper Junos=15.1x49-d55
Juniper Junos=15.1x49-d60
Juniper Junos=15.1x49-d65
Juniper Junos=15.1x49-d70
Juniper Junos=15.1x49-d75
Juniper Junos=15.1x49-d80
Juniper Junos=15.1x49-d90
Juniper Junos=16.1
Juniper Junos=16.1-r1
Juniper Junos=16.1-r2
Juniper Junos=16.1-r3
Juniper Junos=16.1-r3-s10
Juniper Junos=16.1-r3-s11
Juniper Junos=16.1-r4
Juniper Junos=16.1-r4-s12
Juniper Junos=16.1-r4-s2
Juniper Junos=16.1-r4-s3
Juniper Junos=16.1-r4-s4
Juniper Junos=16.1-r4-s6
Juniper Junos=16.1-r5
Juniper Junos=16.1-r5-s4
Juniper Junos=16.1-r6-s1
Juniper Junos=16.1-r6-s6
Juniper Junos=16.1-r7
Juniper Junos=16.1-r7-s2
Juniper Junos=16.1-r7-s3
Juniper Junos=16.1-r7-s4
Juniper Junos=16.1-r7-s5
Juniper Junos=16.1-r7-s6
Juniper Junos=16.1-r7-s7
Juniper Junos=17.2
Juniper Junos=17.2-r1
Juniper Junos=17.2-r1-s1
Juniper Junos=17.2-r1-s2
Juniper Junos=17.2-r1-s3
Juniper Junos=17.2-r1-s4
Juniper Junos=17.2-r1-s5
Juniper Junos=17.2-r1-s7
Juniper Junos=17.2-r1-s8
Juniper Junos=17.2-r2
Juniper Junos=17.2-r2-s11
Juniper Junos=17.2-r2-s6
Juniper Junos=17.2-r2-s7
Juniper Junos=17.2-r3-s1
Juniper Junos=17.2-r3-s2
Juniper Junos=17.2-r3-s3
Juniper Junos=17.3
Juniper Junos=17.3-r1-s1
Juniper Junos=17.3-r2
Juniper Junos=17.3-r2-s1
Juniper Junos=17.3-r2-s2
Juniper Junos=17.3-r2-s3
Juniper Junos=17.3-r2-s4
Juniper Junos=17.3-r2-s5
Juniper Junos=17.3-r3
Juniper Junos=17.3-r3-s1
Juniper Junos=17.3-r3-s2
Juniper Junos=17.3-r3-s3
Juniper Junos=17.3-r3-s4
Juniper Junos=17.3-r3-s7
Juniper Junos=17.4
Juniper Junos=17.4-r1
Juniper Junos=17.4-r1-s1
Juniper Junos=17.4-r1-s2
Juniper Junos=17.4-r1-s4
Juniper Junos=17.4-r1-s5
Juniper Junos=17.4-r1-s6
Juniper Junos=17.4-r1-s7
Juniper Junos=17.4-r2
Juniper Junos=17.4-r2-s1
Juniper Junos=17.4-r2-s10
Juniper Junos=17.4-r2-s2
Juniper Junos=17.4-r2-s3
Juniper Junos=17.4-r2-s4
Juniper Junos=17.4-r2-s5
Juniper Junos=17.4-r2-s6
Juniper Junos=17.4-r2-s7
Juniper Junos=17.4-r2-s8
Juniper Junos=17.4-r2-s9
Juniper Junos=18.1
Juniper Junos=18.1-r1
Juniper Junos=18.1-r2
Juniper Junos=18.1-r2-s1
Juniper Junos=18.1-r2-s2
Juniper Junos=18.1-r2-s4
Juniper Junos=18.1-r3
Juniper Junos=18.1-r3-s1
Juniper Junos=18.1-r3-s2
Juniper Junos=18.1-r3-s3
Juniper Junos=18.1-r3-s4
Juniper Junos=18.1-r3-s6
Juniper Junos=18.2
Juniper Junos=18.2-r1
Juniper Junos=18.2-r1
Juniper Junos=18.2-r1-s3
Juniper Junos=18.2-r1-s4
Juniper Junos=18.2-r1-s5
Juniper Junos=18.2-r2
Juniper Junos=18.2-r2-s1
Juniper Junos=18.2-r2-s2
Juniper Junos=18.2-r2-s3
Juniper Junos=18.2-r2-s4
Juniper Junos=18.2-r2-s5
Juniper Junos=18.2-r2-s6
Juniper Junos=18.3
Juniper Junos=18.3-r1
Juniper Junos=18.3-r1-s1
Juniper Junos=18.3-r1-s2
Juniper Junos=18.3-r1-s3
Juniper Junos=18.3-r1-s5
Juniper Junos=18.3-r1-s6
Juniper Junos=18.3-r2
Juniper Junos=18.3-r2-s1
Juniper Junos=18.3-r2-s2
Juniper Junos=18.3-r2-s3
Juniper Junos=18.4
Juniper Junos=18.4-r1
Juniper Junos=18.4-r1-s1
Juniper Junos=18.4-r1-s2
Juniper Junos=18.4-r1-s5
Juniper Junos=18.4-r1-s6
Juniper Junos=19.1
Juniper Junos=19.1-r1
Juniper Junos=19.1-r1-s1
Juniper Junos=19.1-r1-s2
Juniper Junos=19.1-r1-s3
Juniper Junos=19.1-r1-s4
Juniper Junos=19.2
Juniper Junos=19.2-r1
Juniper Junos=19.2-r1-s1
Juniper Junos=19.2-r1-s2
Juniper Junos=19.2-r1-s3
Juniper NFX150
Juniper NFX250
Juniper NFX350
Juniper SRX1500
Juniper SRX300
Juniper SRX320
Juniper SRX340
Juniper SRX345
Juniper Srx380
Juniper SRX4100
Juniper SRX4200
Juniper SRX4600
Juniper SRX5400
Juniper SRX550
Juniper SRX5600
Juniper SRX5800

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos OS 12.3X48-D105, 15.1X49-D190, 16.1R7-S8, 17.2R3-S4, 17.3R3-S8, 17.4R2-S11, 17.4R3, 18.1R3-S7, 18.2R3, 18.3R2-S4, 18.3R3, 18.4R1-S7, 18.4R2, 18.4R3, 19.1R2, 19.2R1-S4, 19.2R2, 19.3R1, and all subsequent releases.

Event History

Oct 16, 2020
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2020-1688?

CVE-2020-1688 has a medium severity level due to its potential impact on the confidentiality of private keys.

2

How do I fix CVE-2020-1688?

To fix CVE-2020-1688, upgrade to the recommended Juniper JUNOS software version as specified in the security advisory.

3

Who is affected by CVE-2020-1688?

CVE-2020-1688 affects local authenticated users on Juniper Networks SRX Series and NFX Series devices.

4

What aspect of security does CVE-2020-1688 compromise?

CVE-2020-1688 compromises the confidentiality of the Web API service private key used for encryption.

5

What types of Junos versions are affected by CVE-2020-1688?

Versions of Junos ranging from 12.3x48 to 19.4 are affected by CVE-2020-1688.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203