Juniper Junos SRX Series Console Port Logout Bug Lets Local Users Gain Administrative Access
|
SecurityTracker Alert ID: 1032091 |
SecurityTracker URL: http://securitytracker.com/id/1032091
|
CVE Reference:
CVE-2015-3002
(Links to External Site)
|
Date: Apr 11 2015
|
Impact:
Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): SRX Series; JunOS 12.1X44, 12.1X46, and 12.1X47
|
Description:
A vulnerability was reported in Juniper Junos SRX Series. A local physically user can gain access on the target system.
The "log-out-on-disconnect" feature that is configured via the system port console ("stanza") may not disconnect a user after a system reboot. A physically local user may be able to reconnect to the console port and gain full administrative access.
The vendor has assigned PR 1000407 to this vulnerability.
|
Impact:
A physically local user can gain full administrative access.
|
Solution:
The vendor has issued a fix (12.1X44-D45, 12.1X46-D30, 12.1X47-D15, 12.3X48-D10).
The vendor's advisory is available at:
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10672
|
Vendor URL: kb.juniper.net/InfoCenter/index?page=content&id=JSA10672 (Links to External Site)
|
Cause:
Access control error
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|