CVE detail

CVE-2020-1662 — CVE-2020-1662

Published 2020-10-16 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.5
CVSS v3
0–10 scale
0.0129
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limiting the attack surface to configured BGP peers. This issue only affects devices with BGP damping in combination with accepted-prefix-limit configuration. When the issue occurs the following messages will appear in the /var/log/messages: rpd[6046]: %DAEMON-4-BGP_PREFIX_THRESH_EXCEEDED: XXXX (External AS x): Configured maximum accepted prefix-limit threshold(1800) exceeded for inet6-unicast nlri: 1984 (instance master) rpd[6046]: %DAEMON-3-BGP_CEASE_PREFIX_LIMIT_EXCEEDED: 2001:x:x:x::2 (External AS x): Shutting down peer due to exceeding configured maximum accepted prefix-limit(2000) for inet6-unicast nlri: 2001 (instance master) rpd[6046]: %DAEMO

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: Junos OS: 17.2R3-S4, 17.3R3-S8, 17.3R3-S9, 17.4R2-S10, 17.4R3-S2, 18.1R3-S10, 18.2R3-S4, 18.2X75-D53, 18.2X75-D65, 18.3R2-S4, 18.3R3-S2, 18.4R2-S5, 18.4R3-S2, 19.1R2-S2, 19.1R3-S1, 19.2R1-S5, 19.2R2, 19.3R2-S3, 19.3R3, 19.4R1-S3, 19.4R2, 20.1R1-S2, 20.1R2, 20.2R1, and all subsequent releases. Junos OS Evolved: 20.1R2-EVO, and all subsequent releases.

workarounds

There are multiple workarounds that can be applied to prevent this issue: 1. Disable BGP router flap damping. 2. Replace "accepted-prefix-limit" with "prefix-limit" in the BGP configuration, for example: [edit protocols bgp group ${GRP} neighbor ${NEI} family ${AFI} unicast] + prefix-limit { - accepted-prefix-limit { 3. Make sure that the BGP session idle-timeout is longer than damping max-suppress time. In other words, by the time a peer is eligible to establish BGP session again, no previously advertised prefixes remain suppressed. The BGP session idle time out is configured under: [protocols bgp damping ... teardown <TEARDOWN_VALUE> idle-timeout <IDLE_TIMEOUT_VALUE>] The BGP damping max-suppress time configured under: [protocol bgp damping... max-suppress <MAX_SUPPRES_VALUE>] The <IDLE_TIMEOUT_VALUE> needs to be higher than <MAX_SUPPRES_VALUE>

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=17.3R3-S3<17.3*17.3*advisory ↗
Juniper Networks Junos OS>=17.4R2-S4, 17.4R3<17.4*17.4*advisory ↗
Juniper Networks Junos OS>=18.1R3-S6<18.1*18.1*advisory ↗
Juniper Networks Junos OS>=18.2R3<18.2*18.2*advisory ↗
Juniper Networks Junos OS>=18.2X75-D50, 18.2X75-D60<18.2X75*18.2X75*advisory ↗
Juniper Networks Junos OS>=18.3R2<18.3*18.3*advisory ↗
Juniper Networks Junos OS>=18.4R2<18.4*18.4*advisory ↗
Juniper Networks Junos OS>=19.1R1<19.1*19.1*advisory ↗
Juniper Networks Junos OS>=19.2R1<19.2*19.2*advisory ↗
Juniper Networks Junos OS>=19.3<19.3R2-S3, 19.3R319.3R2-S3, 19.3R3advisory ↗
Juniper Networks Junos OS>=19.4<19.4R1-S3, 19.4R219.4R1-S3, 19.4R2advisory ↗
Juniper Networks Junos OS>=20.1<20.1R1-S2, 20.1R220.1R1-S2, 20.1R2advisory ↗
Juniper Networks Junos OS Evolved>=20.1-EVO<20.1R2-EVO20.1R2-EVOadvisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.