CVE-2020-1613 describes a vulnerability in the BGP FlowSpec implementation of Juniper Networks Junos OS, affecting numerous versions across various product lines including SRX, EX, QFX, and NFX Series devices. A specially crafted BGP FlowSpec advertisement can cause a vulnerable Junos OS device to terminate an established BGP session with the originating peer, potentially propagating this issue to other vulnerable devices downstream. This vulnerability carries a CVSS score of 7.5 (High), indicating a significant impact. It is a network-based attack (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N). The primary impact is high availability loss (A:H) due to BGP session termination, with no confidentiality or integrity impact (C:N/I:N). Currently, there is no evidence of active exploitation, nor is exploit code available in common repositories like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:-:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:-:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.