CVE-2020-1644 is a vulnerability in Juniper Networks Junos OS and Junos OS Evolved that allows a specially crafted BGP UPDATE packet to cause an incorrect internal counter increment, leading to a routing protocols process (RPD) crash and restart. This issue impacts both IBGP and EBGP multihop deployments in IPv4 or IPv6 networks across numerous Junos OS versions prior to their respective patches, and all Junos OS Evolved releases prior to 20.1R2-EVO. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a high severity. It can be exploited remotely over the network (AV:N) with low attack complexity (AC:L) and requires no privileges (PR:N) or user interaction (UI:N). The primary impact is a denial of service (A:H) due to the RPD crash, with no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.2x75CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.2x75:-:*:*:*:*:*:* | ||
17.2x75CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.2x75:d102:*:*:*:*:*:* | ||
17.2x75CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.2x75:d50:*:*:*:*:*:* | ||
17.2x75CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.2x75:d70:*:*:*:*:*:* | ||
17.2x75CPE matchmatch criteria | cpe:2.3:o:juniper:junos:17.2x75:d92:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.