The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.
2015-07-14T17:59:03.400
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x46 | Yes |
Operating System | juniper | junos | 12.1x47 | Yes |
Operating System | juniper | junos | 12.1x47 | Yes |
Operating System | juniper | junos | 12.1x47 | Yes |
Operating System | juniper | junos | 12.3x48 | Yes |
Operating System | juniper | junos | 12.3x48 | Yes |
Operating System | juniper | junos | 12.3x48 | Yes |