Memory leak in Junos OS - CVE-2020-1603

 

Memory leak in Junos OS - CVE-2020-1603

Published: January 3, 2020 / Updated: October 26, 2023


Vulnerability identifier: #VU82433
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1603
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to a crash the entire system.

Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE.


Affected software

Junos OS

How to mitigate CVE-2020-1603

Install updates from vendor's website.

Junos OS - addressed in versions 16.1R7-S6, 16.2R2-S11, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S6, 17.3R3-S6, 17.4R2-S5, 17.4R3, 18.1R3-S7, 18.2X75-D50, 18.2X75-D410, 18.2R3-S2, 18.3R1-S6, 18.3R2-S2, 18.3R3, 18.4R2-S2, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S2, 19.2R2, 19.3R1

External References

Related Security Bulletins