PT-2015-6046 · Juniper Networks · Junos
Published
2015-04-10
·
Updated
2016-12-03
·
CVE-2015-3002
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Junos versions prior to 12.1X44-D45
Juniper Junos versions prior to 12.1X46-D30
Juniper Junos versions prior to 12.1X47-D15
Juniper Junos versions prior to 12.3X48-D10
Description
The issue is related to the log-out-on-disconnect feature when configured in the system port console stanza. This allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.
Recommendations
For versions prior to 12.1X44-D45, update to 12.1X44-D45 or later.
For versions prior to 12.1X46-D30, update to 12.1X46-D30 or later.
For versions prior to 12.1X47-D15, update to 12.1X47-D15 or later.
For versions prior to 12.3X48-D10, update to 12.3X48-D10 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos