CVE-2020-1631 is a critical local file inclusion (LFI) and path traversal vulnerability affecting Juniper Networks Junos OS devices with HTTP/HTTPS services enabled. This flaw allows unauthenticated attackers to read sensitive files, inject commands into logs, or, if J-Web is enabled, gain administrator access by hijacking active J-Web sessions. The severity of this vulnerability ranges from CVSS 5.9 (high impact on confidentiality) to 8.8 (high impact on confidentiality, integrity, and availability) depending on the configuration, with the highest score when J-Web is active. The attack vector is network-based, and exploitation complexity is low, requiring no user interaction. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog. While no public Metasploit or ExploitDB modules exist, it has garnered significant community discussion and media coverage, indicating widespread awareness and potential for further exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:-:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:r1:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:r10:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:r10-s1:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3:r10-s2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.