PT-2016-4683 · Juniper Networks · Junos

Published

2016-09-09

·

Updated

2017-09-01

·

CVE-2016-1280

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Junos OS versions prior to 12.1X44-D52 Junos OS versions prior to 12.1X46-D37 Junos OS versions prior to 12.1X47-D30 Junos OS versions prior to 12.3R12 Junos OS versions prior to 12.3X48-D20 Junos OS versions prior to 13.3R10 Junos OS versions prior to 14.1R8 Junos OS versions prior to 14.1X53-D40 Junos OS versions prior to 14.2R7 Junos OS versions prior to 15.1R4 Junos OS versions prior to 15.1X49-D20 Junos OS versions prior to 15.1X53-D60 Junos OS versions prior to 16.1R1
Description The issue allows remote attackers to bypass an intended certificate validation mechanism via a self-signed certificate with an Issuer name that matches a valid CA certificate enrolled in Junos.
Recommendations For versions prior to 12.1X44-D52, update to 12.1X44-D52 or later. For versions prior to 12.1X46-D37, update to 12.1X46-D37 or later. For versions prior to 12.1X47-D30, update to 12.1X47-D30 or later. For versions prior to 12.3R12, update to 12.3R12 or later. For versions prior to 12.3X48-D20, update to 12.3X48-D20 or later. For versions prior to 13.3R10, update to 13.3R10 or later. For versions prior to 14.1R8, update to 14.1R8 or later. For versions prior to 14.1X53-D40, update to 14.1X53-D40 or later. For versions prior to 14.2R7, update to 14.2R7 or later. For versions prior to 15.1R4, update to 15.1R4 or later. For versions prior to 15.1X49-D20, update to 15.1X49-D20 or later. For versions prior to 15.1X53-D60, update to 15.1X53-D60 or later. For versions prior to 16.1R1, update to 16.1R1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1280

Affected Products

Junos