PT-2016-1751 · Juniper Networks · Junos

Publicado

2016-04-15

·

Atualizado

2016-12-03

·

CVE-2016-1267

CVSS v3.1

6.7

Média

VetorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos versions prior to 12.1X44-D55 Junos versions prior to 12.1X46-D40 Junos versions prior to 12.1X47-D25 Junos versions prior to 12.3R11 Junos versions prior to 12.3X48-D20 Junos versions prior to 13.2R8 Junos versions prior to 13.2X51-D39 Junos versions prior to 13.3R7 Junos versions prior to 14.1R6 Junos versions prior to 14.1X53-D30 Junos versions prior to 14.2R3-S4 Junos versions prior to 15.1F2 Junos versions prior to 15.1R2 Junos versions prior to 15.1X49-D20 Junos versions prior to 16.1R1
Description A race condition exists in the RPC functionality of Junos due to insufficient checking of resource state when it can be shared. This can be exploited by a local attacker to read, delete, or modify arbitrary files.
Recommendations For versions prior to 12.1X44-D55, update to 12.1X44-D55 or later. For versions prior to 12.1X46-D40, update to 12.1X46-D40 or later. For versions prior to 12.1X47-D25, update to 12.1X47-D25 or later. For versions prior to 12.3R11, update to 12.3R11 or later. For versions prior to 12.3X48-D20, update to 12.3X48-D20 or later. For versions prior to 13.2R8, update to 13.2R8 or later. For versions prior to 13.2X51-D39, update to 13.2X51-D39 or later. For versions prior to 13.3R7, update to 13.3R7 or later. For versions prior to 14.1R6, update to 14.1R6 or later. For versions prior to 14.1X53-D30, update to 14.1X53-D30 or later. For versions prior to 14.2R3-S4, update to 14.2R3-S4 or later. For versions prior to 15.1F2, update to 15.1F2 or later. For versions prior to 15.1R2, update to 15.1R2 or later. For versions prior to 15.1X49-D20, update to 15.1X49-D20 or later. For versions prior to 16.1R1, update to 16.1R1 or later.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01077
CVE-2016-1267

Produtos afetados

Junos