PT-2016-1752 · Juniper Networks · Junos

Published

2016-04-15

·

Updated

2016-12-03

·

CVE-2016-1264

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions prior to 12.1X44-D55 Junos OS versions prior to 12.1X46-D40 Junos OS versions prior to 12.1X47-D25 Junos OS versions prior to 12.3R11 Junos OS versions prior to 12.3X48-D20 Junos OS versions prior to 12.3X50-D50 Junos OS versions prior to 13.2R8 Junos OS versions prior to 13.2X51-D39 Junos OS versions prior to 13.2X52-D30 Junos OS versions prior to 13.3R7 Junos OS versions prior to 14.1R6 Junos OS versions prior to 14.1X53-D30 Junos OS versions prior to 14.2R4 Junos OS versions prior to 15.1F2 Junos OS versions prior to 15.1R2 Junos OS versions prior to 15.1X49-D10 Junos OS versions prior to 15.1X49-D20 Junos OS versions prior to 16.1R1
Description The issue exists due to insufficient checking of resource state when it can be shared. Exploitation may allow a remote attacker to elevate privileges using the URL option. This can be achieved through a race condition in the Op command.
Recommendations For Junos OS versions prior to 12.1X44-D55, update to version 12.1X44-D55 or later. For Junos OS versions prior to 12.1X46-D40, update to version 12.1X46-D40 or later. For Junos OS versions prior to 12.1X47-D25, update to version 12.1X47-D25 or later. For Junos OS versions prior to 12.3R11, update to version 12.3R11 or later. For Junos OS versions prior to 12.3X48-D20, update to version 12.3X48-D20 or later. For Junos OS versions prior to 12.3X50-D50, update to version 12.3X50-D50 or later. For Junos OS versions prior to 13.2R8, update to version 13.2R8 or later. For Junos OS versions prior to 13.2X51-D39, update to version 13.2X51-D39 or later. For Junos OS versions prior to 13.2X52-D30, update to version 13.2X52-D30 or later. For Junos OS versions prior to 13.3R7, update to version 13.3R7 or later. For Junos OS versions prior to 14.1R6, update to version 14.1R6 or later. For Junos OS versions prior to 14.1X53-D30, update to version 14.1X53-D30 or later. For Junos OS versions prior to 14.2R4, update to version 14.2R4 or later. For Junos OS versions prior to 15.1F2, update to version 15.1F2 or later. For Junos OS versions prior to 15.1R2, update to version 15.1R2 or later. For Junos OS versions prior to 15.1X49-D10, update to version 15.1X49-D10 or later. For Junos OS versions prior to 15.1X49-D20, update to version 15.1X49-D20 or later. For Junos OS versions prior to 16.1R1, update to version 16.1R1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01078
CVE-2016-1264

Affected Products

Junos