PT-2016-1751 · Juniper Networks · Junos

Published

2016-04-15

·

Updated

2016-12-03

·

CVE-2016-1267

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos versions prior to 12.1X44-D55 Junos versions prior to 12.1X46-D40 Junos versions prior to 12.1X47-D25 Junos versions prior to 12.3R11 Junos versions prior to 12.3X48-D20 Junos versions prior to 13.2R8 Junos versions prior to 13.2X51-D39 Junos versions prior to 13.3R7 Junos versions prior to 14.1R6 Junos versions prior to 14.1X53-D30 Junos versions prior to 14.2R3-S4 Junos versions prior to 15.1F2 Junos versions prior to 15.1R2 Junos versions prior to 15.1X49-D20 Junos versions prior to 16.1R1
Description A race condition exists in the RPC functionality of Junos due to insufficient checking of resource state when it can be shared. This can be exploited by a local attacker to read, delete, or modify arbitrary files.
Recommendations For versions prior to 12.1X44-D55, update to 12.1X44-D55 or later. For versions prior to 12.1X46-D40, update to 12.1X46-D40 or later. For versions prior to 12.1X47-D25, update to 12.1X47-D25 or later. For versions prior to 12.3R11, update to 12.3R11 or later. For versions prior to 12.3X48-D20, update to 12.3X48-D20 or later. For versions prior to 13.2R8, update to 13.2R8 or later. For versions prior to 13.2X51-D39, update to 13.2X51-D39 or later. For versions prior to 13.3R7, update to 13.3R7 or later. For versions prior to 14.1R6, update to 14.1R6 or later. For versions prior to 14.1X53-D30, update to 14.1X53-D30 or later. For versions prior to 14.2R3-S4, update to 14.2R3-S4 or later. For versions prior to 15.1F2, update to 15.1F2 or later. For versions prior to 15.1R2, update to 15.1R2 or later. For versions prior to 15.1X49-D20, update to 15.1X49-D20 or later. For versions prior to 16.1R1, update to 16.1R1 or later.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01077
CVE-2016-1267

Affected Products

Junos