CVE-2020-1647
published 2020-07-17CVE-2020-1647: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.65%
84.0th percentile
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP message. Continued processing of this specific HTTP message may result in an extended Denial of Service (DoS). The offending HTTP message that causes this issue may originate both from the HTTP server or the client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS prior to 18.1R1.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 18.1 < 18.1R3-S9 | 18.1R3-S9 |
| juniper_networks | junos_os | >= 18.2 < 18.2R3-S3 | 18.2R3-S3 |
| juniper_networks | junos_os | >= 18.3 < 18.3R2-S4, 18.3R3-S1 | 18.3R2-S4, 18.3R3-S1 |
| juniper_networks | junos_os | >= 18.4 < 18.4R2-S5, 18.4R3 | 18.4R2-S5, 18.4R3 |
| juniper_networks | junos_os | >= 19.1 < 19.1R2 | 19.1R2 |
| juniper_networks | junos_os | >= 19.2 < 19.2R1-S2, 19.2R2 | 19.2R1-S2, 19.2R2 |
| juniper_networks | junos_os | >= 19.3 < 19.3R2 | 19.3R2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: a specific HTTP message processed by the ICAP redirect service on Juniper SRX Series causes a double free, enabling DoS or RCE. Monitor for anomalous HTTP traffic directed at or proxied through the ICAP redirect service. ↗
- →The malicious HTTP message may originate from either the HTTP server or the HTTP client side — inspect both directions of HTTP traffic passing through the ICAP redirect service. ↗
- ·Vulnerability only affects Juniper SRX Series devices with ICAP redirect service explicitly enabled. Devices without this feature enabled are not affected. ↗
- ·Affected Junos OS versions on SRX Series: 18.1 prior to 18.1R3-S9; 18.2 prior to 18.2R3-S3; 18.3 prior to 18.3R2-S4/18.3R3-S1; 18.4 prior to 18.4R2-S5/18.4R3; 19.1 prior to 19.1R2; 19.2 prior to 19.2R1-S2/19.2R2; 19.3 prior to 19.3R2. Junos OS prior to 18.1R1 is not affected. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w82-5jc2-rr7m: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a De
ghsa_unreviewed·2022-05-24
CVE-2020-1647 [MEDIUM] GHSA-9w82-5jc2-rr7m: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a De
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP message. Continued processing of this specific HTTP message may result in an extended Denial of Service (DoS). The offending HTTP message that causes this issue may originate both from the HTTP server or the client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affec
Juniper
CVE-2020-1647: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a De
vendor_juniper·2020-07-17·CVSS 9.8
CVE-2020-1647 [CRITICAL] CWE-415 CVE-2020-1647: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a De
CVE-2020-1647: On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP message. Continued processing of this specific HTTP message may result in an extended Denial of Service (DoS). The offending HTTP message that causes this issue may originate both from the HTTP server or the client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue
No detection rules found.
No public exploits indexed.
2020-07-17
Published