目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2020-1629— Juniper Networks Junos OS 竞争条件问题漏洞

CVSS 5.9 · Medium EPSS 0.31% · P55
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2020-1629の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Junos OS: A race condition vulnerability may cause RPD daemon to crash when processing a BGP NOTIFICATION message.
ソース: NVD (National Vulnerability Database)
脆弱性説明
A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S3; 17.2 version 17.2R2 and later versions; 17.2X75 versions prior to 17.2X75-D105, 17.2X75-D110; 17.3 versions prior to 17.3R2-S5, 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S3; 18.2X75 versions prior to 18.2X75-D410, 18.2X75-D420, 18.2X75-D50, 18.2X75-D60; 18.3 versions prior to 18.3R1-S5, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R2-S2, 18.4R3; 19.1 versions prior to 19.1R1-S2, 19.1R2; 19.2 versions prior to 19.2R1-S4, 19.2R2. This issue does not affect Juniper Networks Junos OS prior to version 16.1R1.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
单线程内的竞争条件
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Juniper Networks Junos OS 竞争条件问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Juniper Networks Junos OS是美国瞻博网络(Juniper Networks)公司的一套专用于该公司的硬件设备的网络操作系统。该操作系统提供了安全编程接口和Junos SDK。 Juniper Networks Junos OS中存在竞争条件问题漏洞。远程攻击者可借助特制的BGP NOTIFICATION消息利用该漏洞导致路由协议守护程序(RPD)进程崩溃并重新启动。以下产品及版本受到影响:Juniper Networks Junos OS 16.1版本,16.2版本,17.1版本,
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Juniper NetworksJunos OS 16.1 ~ 16.1R7-S6 -

II. CVE-2020-1629の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2020-1629のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Juniper Networks · 2020-04-08 · 22 CVEs total

CVE-2020-161410.0 CRITICALNFX250 Series: Hardcoded credentials in the vSRX VNF instance.
CVE-2020-16159.8 CRITICALJunos OS: vMX: Default credentials supplied in vMX configuration
CVE-2020-16138.6 HIGHJunos OS: BGP session termination upon receipt of specific BGP FlowSpec advertisement.
CVE-2020-16397.5 HIGHJunos OS: A crafted Ethernet OAM packet received by Junos may cause the Ethernet OAM conne
CVE-2020-16177.5 HIGHJunos OS: PTX1000 and PTX10000 Series, QFX10000 Series using non-AFT architectures: A spec
CVE-2020-16267.5 HIGHJunos OS Evolved: Denial of Service vulnerability in processing high rate of specific pack
CVE-2020-16277.5 HIGHJunos OS: vMX and MX150: Denial of Service vulnerability in packet processing
CVE-2020-16347.5 HIGHJunos OS: High-End SRX Series: Multicast traffic might cause all FPCs to reset.
CVE-2020-16387.5 HIGHJunos OS & Junos OS Evolved: A specific IPv4 packet can lead to FPC restart.
CVE-2020-16377.2 HIGHJunos OS: SRX Series: Unified Access Control (UAC) bypass vulnerability
CVE-2020-16256.5 MEDIUMJunos OS: Kernel memory leak in virtual-memory due to interface flaps
CVE-2020-16186.3 MEDIUMJunos OS: EX and QFX Series: Console port authentication bypass vulnerability
CVE-2020-16196.0 MEDIUMJunos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulner
CVE-2020-16245.5 MEDIUMJunos OS Evolved: objmon logs may leak sensitive information
CVE-2020-16225.5 MEDIUMJunos OS Evolved: EvoSharedObjStore may leak sensitive information
CVE-2020-16235.5 MEDIUMJunos OS Evolved: ev.ops file may leak sensitive information
CVE-2020-16205.5 MEDIUMJunos OS Evolved: Configd leaks hashes via log file and is world readable
CVE-2020-16215.5 MEDIUMJunos OS Evolved: Configd leaks hashes via stream and is world readable
CVE-2020-16285.3 MEDIUMJunos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwa
CVE-2020-16165.3 MEDIUMJATP Series: JATP Is susceptible to slow brute force attacks on the SSH service.

Showing 20 of 22 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2020-1629へのコメント

まだコメントはありません


コメントを残す