PT-2017-8608 · Juniper Networks · Junos
Published
2017-10-13
·
Updated
2019-10-09
·
CVE-2016-4924
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions 15.1 prior to 15.1F5
Juniper Networks Junos OS versions 14.1 prior to 14.1R8
Description
An issue in Juniper Networks Junos OS on vMX allows local unprivileged users on a host system to have read access to vMX or vPFE images. This access can lead to the exposure of sensitive information, including private cryptographic keys. The issue was discovered during internal product security testing, and there is no known case of malicious exploitation.
Recommendations
For Juniper Networks Junos OS versions 15.1 prior to 15.1F5, update to version 15.1F5 or later.
For Juniper Networks Junos OS versions 14.1 prior to 14.1R8, update to version 14.1R8 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos