CVE-2020-1678 is a medium-severity memory leak vulnerability affecting Juniper Networks Junos OS and Junos OS Evolved platforms when EVPN is configured. Receipt of specific BGP packets can cause a slow memory leak in the rpd process, potentially leading to a crash if memory is exhausted. This vulnerability has a CVSS score of 6.5, indicating an adjacent network attack vector with low complexity and high impact on availability. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules available. While there are 2 community mentions and 1 media article, these appear to be misattributions to a different CVE (CVE-2021-1678), suggesting low actual community attention for CVE-2020-1678.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.4:r1:*:*:*:*:*:* | ||
19.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.4:r1-s1:*:*:*:*:*:* | ||
19.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.4:r1-s2:*:*:*:*:*:* | ||
20.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.1:r1:*:*:*:*:*:* | ||
20.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.1:r1-s1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.