CVE-2020-1613
Last modified
CVE-2020-1613 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability in the BGP FlowSpec implementation may cause a Juniper Networks Junos OS device to terminate an established BGP session upon receiving a specific BGP FlowSpec advertisement. The BGP NOTIFICATION message that terminates an established BGP session is sent toward the peer device that originally sent the specific BGP FlowSpec advertisement. EPSS estimates a 1.29% chance of exploitation in the next 30 days.
Description
A vulnerability in the BGP FlowSpec implementation may cause a Juniper Networks Junos OS device to terminate an established BGP session upon receiving a specific BGP FlowSpec advertisement. The BGP NOTIFICATION message that terminates an established BGP session is sent toward the peer device that originally sent the specific BGP FlowSpec advertisement. This specific BGP FlowSpec advertisement received from a BGP peer might get propagated from a Junos OS device running the fixed release to another device that is vulnerable causing BGP session termination downstream. This issue affects IPv4 and IPv6 BGP FlowSpec deployment. This issue affects Juniper Networks Junos OS: 12.3; 12.3X48 on SRX Series; 14.1X53 on EX and QFX Series; 15.1 versions prior to 15.1R7-S5; 15.1F versions prior to 15.1F6-S13; 15.1X49 versions prior to 15.1X49-D180 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110; 15.1X53 versions prior to 15.1X53-D497 on NFX Series; 15.1X53 versions prior to 15.1X53-D592 on EX2300/EX3400; 16.1 versions prior to 16.1R7-S7; 17.1 versions prior to 17.1R2-S12, 17.1R3; 17.2 versions prior to 17.2R2-S7, 17.2R3; 17.2X75 versions prior to 17.2X75-D102, 17.2X75-D110, 17.2X75-D44; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R1-S8, 17.4R2; 18.1 versions prior to 18.1R2-S4, 18.1R3; 18.2X75 versions prior to 18.2X75-D20.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 12.3 | — |
| Juniper | Junos | 15.1 | — |
| Juniper | Junos | 16.1 | — |
| Juniper | Junos | 17.1 | — |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.2x75 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2x75 | — |
| Juniper | Junos | 18.2x75-d10 | — |
| Juniper | Junos | 12.3x48 | D10 |
| Juniper | Junos | 15.1x49 | — |
| Juniper | Junos | 14.1x53 | — |
| Juniper | Junos | 15.1x53 | — |
| Juniper | Junos | 15.1x53-d50 | — |
| Juniper | Junos | 15.1x53-d51 | — |
| Juniper | Junos | 15.1x53-d52 | — |
| Juniper | Junos | 15.1x53-d55 | — |
| Juniper | Junos | 15.1x53-d57 | — |
| Juniper | Junos | 15.1x53-d58 | — |
| Juniper | Junos | 15.1x53-d59 | — |
References
- https://kb.juniper.net/JSA10996Vendor Advisory
- https://kb.juniper.net/JSA10996Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1613?
How severe is CVE-2020-1613?
How do I fix CVE-2020-1613?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-16123An Ubuntu-specific patch in PulseAudio created a race condit…4.7
- CVE-2020-16124Integer Overflow or Wraparound vulnerability in the XML RPC …9.8
- CVE-2020-16125gdm3 versions before 3.36.2 or 3.38.2 would start gnome-init…6.8
- CVE-2020-16126An Ubuntu-specific modification to AccountsService in versio…3.3
- CVE-2020-16127An Ubuntu-specific modification to AccountsService in versio…5.5
- CVE-2020-16128The aptdaemon DBus interface disclosed file existence disclo…3.8
- CVE-2020-16131Tiki before 21.2 allows XSS because [\s\/"\'] is not properl…6.1
- CVE-2020-16132Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-16134An issue was discovered on Swisscom Internet Box 2, Internet…8
- CVE-2020-16135libssh 0.9.4 has a NULL pointer dereference in tftpserver.c …5.9
- CVE-2020-16136In tgstation-server 4.4.0 and 4.4.1, an authenticated user w…7.7
- CVE-2020-16137A privilege escalation issue in Cisco Unified IP Conference …9.8
Are you affected by CVE-2020-1613?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
