CVE-2020-1685 describes a flaw in Juniper Networks EX4600 and QFX 5000 Series devices using VXLAN, where stateless firewall filters configured with a discard action may fail to drop traffic under specific conditions. This occurs when a filter has only one term with a 'user-vlan-id' match and a subsequent discard action, leading to unintended traffic passage. The vulnerability affects various Junos OS versions across the QFX5K Series. Rated as Medium severity (CVSS 5.8), the vulnerability has a network attack vector and low attack complexity, requiring no user interaction. While it doesn't directly impact confidentiality or availability, it can lead to a low impact on integrity by allowing unauthorized traffic to bypass intended firewall rules. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.1:-:*:*:*:*:*:* | ||
18.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.1:r1:*:*:*:*:*:* | ||
18.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.1:r2:*:*:*:*:*:* | ||
18.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.1:r2-s1:*:*:*:*:*:* | ||
18.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.1:r2-s2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.