CVE-2020-1602 describes a critical vulnerability in Juniper Networks Junos OS and Junos OS Evolved's Dynamic Host Configuration Protocol Daemon (JDHCPD) process when configured in relay mode. An unauthenticated attacker can send specially crafted IPv4 packets to remotely execute arbitrary code on the affected device. This vulnerability carries a CVSS score of 8.8 (High), indicating a severe risk due to its low attack complexity, network-based attack vector, and potential for complete compromise of confidentiality, integrity, and availability. While no known public exploits or active exploitation have been identified, and community discussion is minimal, the potential impact warrants immediate attention for affected versions prior to the specified fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r7:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r7-s1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r7-s2:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r7-s3:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1:r7-s4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.