CVE detail

CVE-2020-1617 — CVE-2020-1617

Published 2020-04-08 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.5
CVSS v3
0–10 scale
0.0157
EPSS probability
exploitation probability, 30d
73.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to this issue. An improper initialization of memory in the packet forwarding architecture in Juniper Networks Junos OS non-AFI/AFT platforms which may lead to a Denial of Service (DoS) vulnerability being exploited when a genuine packet is received and inspected by non-AFT/AFI sFlow and when the device is also configured with firewall policers. This first genuine packet received and inspected by sampled flow (sFlow) through a specific firewall policer will cause the device to reboot. After the reboot has completed, if the device receives and sFlow inspects another genuine packet seen through a spec

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: 17.4R2-S9, 17.4R3;18.2X75-D12, 18.2X75-D30, 18.1R3-S9, 18.2R3, 18.3R3, 18.4R1, and all subsequent releases.

workarounds

Discontinue use of firewall policers. Or Discontinue use of sFlow. Or Both of the above. It is not required to discontinue both to mitigate the issue. There are no other available workarounds.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=17.4<17.4R2-S9, 17.4R317.4R2-S9, 17.4R3advisory ↗
Juniper Networks Junos OS>=18.1<=18.1R3-S918.1R3-S9advisory ↗
Juniper Networks Junos OS>=18.2<18.2R318.2R3advisory ↗
Juniper Networks Junos OS>=18.2X75<18.2X75-D12, 18.2X75-D3018.2X75-D12, 18.2X75-D30advisory ↗
Juniper Networks Junos OS>=18.3<18.3R318.3R3advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.