PT-2015-6867 · Juniper Networks · Junos
Published
2015-07-16
·
Updated
2015-07-22
·
CVE-2015-5360
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Junos versions 12.1X44 before 12.1X44-D51
Junos versions 12.1X46 before 12.1X46-D40
Junos versions 12.1X47 before 12.1X47-D25
Junos versions 12.3 before 12.3R10
Junos versions 12.3X48 before 12.3X48-D20
Junos versions 13.2 before 13.2R8
Junos versions 13.3 before 13.3R6
Junos versions 14.1 before 14.1R5
Junos versions 14.2 before 14.2R3
Junos versions 15.1 before 15.1R1
Junos versions 15.1X49 before 15.1X49-D20
Description
The issue allows remote attackers to cause a denial of service (CPU consumption) via a crafted Secure Neighbor Discovery (SEND) Protocol packet when the "set protocols neighbor-discovery secure security-level default" option is configured.
Recommendations
For Junos versions 12.1X44 before 12.1X44-D51, update to version 12.1X44-D51 or later.
For Junos versions 12.1X46 before 12.1X46-D40, update to version 12.1X46-D40 or later.
For Junos versions 12.1X47 before 12.1X47-D25, update to version 12.1X47-D25 or later.
For Junos versions 12.3 before 12.3R10, update to version 12.3R10 or later.
For Junos versions 12.3X48 before 12.3X48-D20, update to version 12.3X48-D20 or later.
For Junos versions 13.2 before 13.2R8, update to version 13.2R8 or later.
For Junos versions 13.3 before 13.3R6, update to version 13.3R6 or later.
For Junos versions 14.1 before 14.1R5, update to version 14.1R5 or later.
For Junos versions 14.2 before 14.2R3, update to version 14.2R3 or later.
For Junos versions 15.1 before 15.1R1, update to version 15.1R1 or later.
For Junos versions 15.1X49 before 15.1X49-D20, update to version 15.1X49-D20 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos