CVE-2020-1605

Description

When a device using Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute commands as root on the target device. This issue affects IPv4 JDHCPD services. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D592; 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R2-S7, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3-S2; 18.2X75 versions prior to 18.2X75-D60; 18.3 versions prior to 18.3R1-S6, 18.3R2-S2, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S3, 19.2R2*. and All versions prior to 19.3R1 on Junos OS Evolved. This issue do not affect versions of Junos OS prior to 15.1, or JDHCPD operating as a local server in non-relay mode.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.205

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are fixed in junos 15.1R7-S6NCM
Multiple Vulnerabilities are fixed in junos 16.1R7-S6NCM
Multiple Vulnerabilities are fixed in junos 16.2R2-S11NCM
Multiple Vulnerabilities are fixed in junos 17.1r2-s11NCM
Multiple Vulnerabilities are fixed in junos 17.2r2-s8NCM
Multiple Vulnerabilities are fixed in junos 17.3R3-S6NCM
Vulnerabilities CVE-2020-1602,CVE-2020-1605,CVE-2020-1608,CVE-2020-1609 are fixed in junos 17.4R2-S7NCM
Multiple Vulnerabilities are fixed in junos 18.1r3-s8NCM
Multiple Vulnerabilities are fixed in junos 18.2R3-S2NCM
Multiple Vulnerabilities are fixed in junos 18.3R1-S6NCM
Multiple Vulnerabilities are fixed in junos 18.4r1-s5NCM
Multiple Vulnerabilities are fixed in junos 19.1R1-S3NCM
Vulnerabilities CVE-2020-1602,CVE-2020-1605,CVE-2020-1609,CVE-2020-1649 are fixed in junos 19.2r1-s3NCM
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability (CVE-2020-1605)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234