CVE-2020-1601 describes a Denial of Service (DoS) vulnerability in Juniper Networks Junos OS, affecting devices acting as a Path Computation Client (PCC) in a PCEP environment. Malformed PCEP packets can cause the pccd process to crash, leading to a sustained DoS if continuously received. This vulnerability impacts various Junos OS versions across different series, with specific versions listed as vulnerable. The vulnerability has a CVSSv3.1 score of 7.5 (HIGH), indicating a severe impact. It can be exploited remotely over the network (AV:N) with low attack complexity (AC:L), requiring no user interaction (UI:N) or privileges (PR:N), and primarily results in high availability impact (A:H). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:f6-s12:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r2:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r3:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.