Security readout for executives and security teams
Plain-English summary
Certain Juniper High-End SRX firewalls can crash key packet-processing components when handling genuine multicast traffic under specific conditions. The result can be a chassis-wide reset of forwarding cards, causing a denial of service. This is an availability risk for networks relying on affected SRX devices for perimeter or segmentation enforcement.
Executive priority
Prioritize remediation where affected High-End SRX devices protect critical network paths. The main business risk is service disruption, not data theft. Upgrade planning should account for maintenance windows because remediation affects network infrastructure.
Technical view
CVE-2020-1634 affects Junos OS 12.3X48-D80 and later releases before 12.3X48-D95 on High-End SRX Series. In specific configurations and events, multicast traffic can cause an SPC core, followed by all FPCs resetting. The issue affects IPv4 and IPv6 and is associated with CWE-190.
Likely exposure
Exposure is limited to Juniper High-End SRX Series devices running affected Junos OS 12.3X48 releases. Branch SRX Series devices are explicitly not affected. Environments using multicast routing or receiving multicast traffic through these devices deserve focused review.
Exploitation context
The CVE has a network-reachable CVSS vector and requires no privileges or user interaction. The provided sources do not state public exploitation, and the CVE is not marked as CISA KEV. Treat exploitation status as unconfirmed, not actively exploited.
Researcher notes
Key scope details are precise: High-End SRX only, Junos OS 12.3X48-D80 through pre-D95, IPv4 and IPv6 multicast. Sources describe genuine multicast traffic and specific configurations or events, but do not provide exact trigger conditions in the bundle.
Mitigation direction
- Upgrade affected Junos OS systems to 12.3X48-D95 or vendor-advised fixed releases.
- Review Juniper advisory JSA11014 for current remediation guidance.
- Prioritize internet-edge or critical-path High-End SRX devices first.
- Assess multicast exposure and reduce unnecessary multicast reachability where operationally safe.
- Monitor for SPC core events and chassis-wide FPC resets.
Validation and detection
- Inventory High-End SRX devices and installed Junos OS versions.
- Confirm whether versions are 12.3X48-D80 or later before 12.3X48-D95.
- Verify Branch SRX devices are excluded from this finding.
- Review configurations for IPv4 or IPv6 multicast handling.
- Check logs for SPC cores, FPC resets, or multicast-correlated outages.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-190: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2020-1634 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://kb.juniper.net/JSA11014CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Integer Overflow or Wraparound
Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
