← Back

CVE-2015-3002

nvd nist
Published: Apr 10, 2015Modified: May 6, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stanza, which allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.

Affected (22)

Products: Juniper: Junos
1 product
Junos
Configuration A
22 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 12.1x44
Version 12.1x44 d10
Version 12.1x44 d15
Version 12.1x44 d20
Version 12.1x44 d25
Version 12.1x44 d30
Version 12.1x44 d35
Version 12.1x44 d40
Version 12.1x44 d45
Version 12.1x45
Version 12.1x45 d10
Version 12.1x45 d15
Version 12.1x45 d20
Version 12.1x45 d30
Version 12.1x46
Version 12.1x46 d10
Version 12.1x46 d15
Version 12.1x46 d20
Version 12.1x46 d25
Version 12.1x47
Version 12.1x47 d10
Version 12.1x48
Running on/withPlatform Versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx240
All versions
Juniper
Srx3400
All versions
Juniper
Srx3600
All versions
Juniper
Srx550
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.