Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3002


Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stanza, which allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.


Published

2015-04-10T15:00:07.117

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.9 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-17

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x44 Yes
Operating System juniper junos 12.1x45 Yes
Operating System juniper junos 12.1x45 Yes
Operating System juniper junos 12.1x45 Yes
Operating System juniper junos 12.1x45 Yes
Operating System juniper junos 12.1x45 Yes
Operating System juniper junos 12.1x46 Yes
Operating System juniper junos 12.1x46 Yes
Operating System juniper junos 12.1x46 Yes
Operating System juniper junos 12.1x46 Yes
Operating System juniper junos 12.1x46 Yes
Operating System juniper junos 12.1x47 Yes
Operating System juniper junos 12.1x47 Yes
Operating System juniper junos 12.1x48 Yes
Hardware juniper srx100 - No
Hardware juniper srx110 - No
Hardware juniper srx1400 - No
Hardware juniper srx210 - No
Hardware juniper srx220 - No
Hardware juniper srx240 - No
Hardware juniper srx3400 - No
Hardware juniper srx3600 - No
Hardware juniper srx550 - No
Hardware juniper srx5600 - No
Hardware juniper srx5800 - No
Hardware juniper srx650 - No

References