CVE-2020-1679
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2020
Last modified:
05/08/2022
Description
On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process Daemon (RPD) that synchronized the routing tables with the forwarding tables in the kernel. This table is then synchronized to the Packet Forwarding Engine (PFE) via the KRT queue. Thus, when KRT queue become stuck, it can lead to unexpected packet forwarding issues. An administrator can monitor the following command to check if there is the KRT queue is stuck: user@device > show krt state ... Number of async queue entries: 65007
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:juniper:junos:17.2x75:*:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:17.2x75:-:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:17.2x75:d102:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:17.2x75:d50:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:17.2x75:d70:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:17.2x75:d92:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:-:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r2-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r2-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r2-s4:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r3-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:18.1:r3-s10:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page