CVE-2020-1664Stack-based Buffer Overflow in Networks Junos OS

Severity
7.8HIGHNVD
EPSS
0.0%
top 85.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

A stack buffer overflow vulnerability in the device control daemon (DCD) on Juniper Networks Junos OS allows a low privilege local user to create a Denial of Service (DoS) against the daemon or execute arbitrary code in the system with root privilege. This issue affects Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S12, 17.4R3-S3; 18.1 versions prior to 18.1R3-S11; 18.2 versions prior to 18.2R3-S6; 18.2X75 versions prior to 18.2X75-D53, 18.2X75-D65; 1

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5juniper_networks/junos_os17.317.3R3-S9+12
NVDjuniper/junos13 versions+12

🔴Vulnerability Details

2
GHSA
GHSA-2r5v-65wf-9f8p: A stack buffer overflow vulnerability in the device control daemon (DCD) on Juniper Networks Junos OS allows a low privilege local user to create a De2022-05-24
CVEList
Junos OS: Buffer overflow vulnerability in device control daemon2020-10-16

📋Vendor Advisories

1
Juniper
CVE-2020-1664: A stack buffer overflow vulnerability in the device control daemon (DCD) on Juniper Networks Junos OS allows a low privilege local user to create a De2020-10-16
CVE-2020-1664 — Stack-based Buffer Overflow | cvebase