PT-2015-6046 · Juniper Networks · Junos

Publicado

2015-04-10

·

Atualizado

2016-12-03

·

CVE-2015-3002

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Juniper Junos versions prior to 12.1X44-D45 Juniper Junos versions prior to 12.1X46-D30 Juniper Junos versions prior to 12.1X47-D15 Juniper Junos versions prior to 12.3X48-D10
Description The issue is related to the log-out-on-disconnect feature when configured in the system port console stanza. This allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.
Recommendations For versions prior to 12.1X44-D45, update to 12.1X44-D45 or later. For versions prior to 12.1X46-D30, update to 12.1X46-D30 or later. For versions prior to 12.1X47-D15, update to 12.1X47-D15 or later. For versions prior to 12.3X48-D10, update to 12.3X48-D10 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3002

Produtos afetados

Junos