CVE detail

CVE-2020-1603 — CVE-2020-1603

Published 2020-01-15 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
8.6
CVSS v3
0–10 scale
0.0140
EPSS probability
exploitation probability, 30d
70.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which point a mbuf memory leak occurs within the Juniper Networks Junos OS device. This memory leak eventually leads to a kernel crash (vmcore), or the device hanging and requiring a power cycle to restore service, creating a Denial of Service (DoS) condition. During the time where mbufs are rising, yet not fully filled, some traffic from client devices may begin to be black holed. To be black holed, this traffic must match the condition where this traffic must be processed by the RE. Continued receipt and attempted egress of these specific IPv

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 16.1R7-S6, 16.2R2-S11, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R3-S6, 17.4R2-S9, 17.4R3, 18.1R3-S7, 18.2R3-S2, 18.2X75-D50, 18.2X75-D410, 18.3R1-S6, 18.3R2-S2, 18.3R3, 18.4R1-S6, 18.4R2-S2, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S2, 19.2R2, 19.3R1, and all subsequent releases.

workarounds

Remove 'family inet6' from interfaces. Otherwise, there are no available workarounds for this issue. Indicators of compromise can be found by reviewing RE logs for entries which match in " " : "/kernel: Mbuf: High Utililization Level" Additionally, you may issue the follow command from time to time to determine if your mbufs are climbing or are being released by reviewing across two separate times. The required privilege level to run the command is: view. show system buffers

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=16.1<16.1R7-S616.1R7-S6advisory ↗
Juniper Networks Junos OS>=16.2<16.2R2-S1116.2R2-S11advisory ↗
Juniper Networks Junos OS>=17.1<17.1R2-S11, 17.1R3-S117.1R2-S11, 17.1R3-S1advisory ↗
Juniper Networks Junos OS>=17.2<17.2R1-S9, 17.2R2-S8, 17.2R3-S317.2R1-S9, 17.2R2-S8, 17.2R3-S3advisory ↗
Juniper Networks Junos OS>=17.3<17.3R3-S617.3R3-S6advisory ↗
Juniper Networks Junos OS>=17.4<17.4R2-S9, 17.4R317.4R2-S9, 17.4R3advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S718.1R3-S7advisory ↗
Juniper Networks Junos OS>=18.2<18.2R3-S218.2R3-S2advisory ↗
Juniper Networks Junos OS>=18.2X75<18.2X75-D50, 18.2X75-D41018.2X75-D50, 18.2X75-D410advisory ↗
Juniper Networks Junos OS>=18.3<18.3R1-S6, 18.3R2-S2, 18.3R318.3R1-S6, 18.3R2-S2, 18.3R3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S6, 18.4R2-S2, 18.4R318.4R1-S6, 18.4R2-S2, 18.4R3advisory ↗
Juniper Networks Junos OS>=19.1<19.1R1-S3, 19.1R219.1R1-S3, 19.1R2advisory ↗
Juniper Networks Junos OS>=19.2<19.2R1-S2, 19.2R219.2R1-S2, 19.2R2advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.