mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
227 lines
11 KiB
JSON
227 lines
11 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "sirt@juniper.net",
|
|
"DATE_PUBLIC": "2020-01-08T17:00:00.000Z",
|
|
"ID": "CVE-2020-1609",
|
|
"STATE": "PUBLIC",
|
|
"TITLE": "Junos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device."
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Junos OS",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "15.1",
|
|
"version_value": "15.1R7-S6"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "15.1X49",
|
|
"version_value": "15.1X49-D200"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "15.1X53",
|
|
"version_value": "15.1X53-D592"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "16.1",
|
|
"version_value": "16.1R7-S6"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "16.2",
|
|
"version_value": "16.2R2-S11"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "17.1",
|
|
"version_value": "17.1R2-S11, 17.1R3-S1"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "17.2",
|
|
"version_value": "17.2R2-S8, 17.2R3-S3"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "17.3",
|
|
"version_value": "17.3R3-S6"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "17.4",
|
|
"version_value": "17.4R2-S7, 17.4R3"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "18.1",
|
|
"version_value": "18.1R3-S8"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "18.2",
|
|
"version_value": "18.2R3-S2"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "18.3",
|
|
"version_value": "18.3R1-S6, 18.3R2-S2, 18.3R3"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "18.4",
|
|
"version_value": "18.4R1-S5, 18.4R2-S3, 18.4R3"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "19.1",
|
|
"version_value": "19.1R1-S3, 19.1R2"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "19.2",
|
|
"version_value": "19.2R1-S3, 19.2R2"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "19.3",
|
|
"version_value": "19.3R1, 19.3R2"
|
|
},
|
|
{
|
|
"version_affected": "<",
|
|
"version_name": "18.2X75",
|
|
"version_value": "18.2X75-D60"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "Junos OS Evolved",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"platform": "Junos Evolved",
|
|
"version_affected": "<",
|
|
"version_value": "19.3R1"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name": "Juniper Networks"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"configuration": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "The following minimal configuration is required: \n [forwarding-options dhcp-relay]"
|
|
}
|
|
],
|
|
"credit": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Longfei Fan from Codesafe Team of Legendsec at Qi'anxin Group"
|
|
}
|
|
],
|
|
"data_format": "MITRE",
|
|
"data_type": "CVE",
|
|
"data_version": "4.0",
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute commands as root on the target device. This issue affects IPv6 JDHCPD services. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D592; 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D60; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S3, 19.2R2*. and All versions prior to 19.3R1 on Junos OS Evolved. This issue do not affect versions of Junos OS prior to 15.1, or JDHCPD operating as a local server in non-relay mode."
|
|
}
|
|
]
|
|
},
|
|
"exploit": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
|
|
}
|
|
],
|
|
"generator": {
|
|
"engine": "Vulnogram 0.0.9"
|
|
},
|
|
"impact": {
|
|
"cvss": {
|
|
"attackComplexity": "LOW",
|
|
"attackVector": "ADJACENT_NETWORK",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 8.8,
|
|
"baseSeverity": "HIGH",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"privilegesRequired": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"userInteraction": "NONE",
|
|
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"version": "3.1"
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-121 Stack-based Buffer Overflow"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-78 OS Command Injection"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"name": "https://kb.juniper.net/JSA10981",
|
|
"refsource": "CONFIRM",
|
|
"url": "https://kb.juniper.net/JSA10981"
|
|
},
|
|
{
|
|
"name": "https://prsearch.juniper.net/InfoCenter/index?page=prcontent&id=PR1449353",
|
|
"refsource": "MISC",
|
|
"url": "https://prsearch.juniper.net/InfoCenter/index?page=prcontent&id=PR1449353"
|
|
}
|
|
]
|
|
},
|
|
"solution": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "The following software releases have been updated to resolve this specific issue: \nJunos OS: 15.1R7-S6, 15.1X49-D200, 15.1X53-D592, 16.1R7-S6, 16.2R2-S11, 17.1R2-S11, 17.1R3-S1, 17.2R2-S8, 17.2R3-S3, 17.3R3-S6, 17.4R2-S7, 17.4R3, 18.1R3-S8, 18.2R3-S2, 18.2X75-D60, 18.3R1-S6, 18.3R2-S2, 18.3R3, 18.4R1-S5, 18.4R2-S3, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S3, 19.2R2*, 19.3R1, and all subsequent releases.\n\nJunos OS Evolved: 19.3R1, and all subsequent releases.\n\n*pending publication"
|
|
}
|
|
],
|
|
"source": {
|
|
"advisory": "JSA10981",
|
|
"defect": [
|
|
"1449353"
|
|
],
|
|
"discovery": "EXTERNAL"
|
|
},
|
|
"work_around": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "If JDHCPD is not needed then disable the service in the device configuration. \nThere are no other viable workarounds for this issue."
|
|
}
|
|
]
|
|
} |