ID

VAR-201609-0025


CVE

CVE-2016-1275


TITLE

Juniper Junos OS Important in mbuf Information vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-004593

DESCRIPTION

Juniper Junos OS before 13.3R9, 14.1R6 before 14.1R6-S1, and 14.1 before 14.1R7, when configured with VPLS routing-instances, allows remote attackers to obtain sensitive mbuf information by injecting a flood of Ethernet frames with IPv6 MAC addresses directly into a connected interface. Juniper Junos is prone to a denial-of-service vulnerability. An attacker may exploit this issue to cause denial-of-service conditions. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. The following releases are affected: Juniper Junos OS release 13.3R9, 14.1R6 prior to 14.1R6-S1, 14.1 prior to 14.1R7

Trust: 2.07

sources: NVD: CVE-2016-1275 // JVNDB: JVNDB-2016-004593 // BID: 91758 // VULHUB: VHN-90094 // VULMON: CVE-2016-1275

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:14.1

Trust: 1.9

vendor:junipermodel:junosscope:lteversion:13.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:13.3

Trust: 0.9

vendor:junipermodel:junos osscope:ltversion:14.1

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.1r7

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:14.1r6-s1

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:14.1r6

Trust: 0.8

vendor:junipermodel:junos 14.1r6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r4-s7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r3-s9scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r3-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 14.1r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos r3scope:eqversion:14.1

Trust: 0.3

vendor:junipermodel:junos r2scope:eqversion:14.1

Trust: 0.3

vendor:junipermodel:junos r1scope:eqversion:14.1

Trust: 0.3

vendor:junipermodel:junos 13.3r8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r7-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r4.6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r3-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2-s3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2-s2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r1.8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r1.7scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 13.3r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos r5scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos r4scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos r3scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos r2-s2scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos r2scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos r1scope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos 16.1r1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 15.1r1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 15.1f2scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 14.2r1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 14.1r7scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 14.1r6-s1scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 13.3r9scope:neversion: -

Trust: 0.3

sources: BID: 91758 // JVNDB: JVNDB-2016-004593 // CNNVD: CNNVD-201607-420 // NVD: CVE-2016-1275

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-1275
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-1275
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201607-420
value: MEDIUM

Trust: 0.6

VULHUB: VHN-90094
value: MEDIUM

Trust: 0.1

VULMON: CVE-2016-1275
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-1275
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-90094
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-1275
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-90094 // VULMON: CVE-2016-1275 // JVNDB: JVNDB-2016-004593 // CNNVD: CNNVD-201607-420 // NVD: CVE-2016-1275

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-90094 // JVNDB: JVNDB-2016-004593 // NVD: CVE-2016-1275

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201607-420

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201607-420

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-004593

PATCH

title:JSA10750url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10750&actp=search

Trust: 0.8

title:Juniper Junos Remediation measures for denial of service vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=62963

Trust: 0.6

title: - url:https://www.theregister.co.uk/2016/07/14/junipers_bug_hunters_fire_out_eight_patches/

Trust: 0.2

title: - url:https://threatpost.com/juniper-crypto-bug-lets-attackers-eavesdrop-on-router-switch-traffic/119319/

Trust: 0.1

sources: VULMON: CVE-2016-1275 // JVNDB: JVNDB-2016-004593 // CNNVD: CNNVD-201607-420

EXTERNAL IDS

db:NVDid:CVE-2016-1275

Trust: 2.9

db:BIDid:91758

Trust: 2.1

db:JUNIPERid:JSA10750

Trust: 2.1

db:SECTRACKid:1036301

Trust: 1.2

db:JVNDBid:JVNDB-2016-004593

Trust: 0.8

db:CNNVDid:CNNVD-201607-420

Trust: 0.7

db:VULHUBid:VHN-90094

Trust: 0.1

db:VULMONid:CVE-2016-1275

Trust: 0.1

sources: VULHUB: VHN-90094 // VULMON: CVE-2016-1275 // BID: 91758 // JVNDB: JVNDB-2016-004593 // CNNVD: CNNVD-201607-420 // NVD: CVE-2016-1275

REFERENCES

url:http://www.securityfocus.com/bid/91758

Trust: 1.8

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10750

Trust: 1.7

url:http://www.securitytracker.com/id/1036301

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1275

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1275

Trust: 0.8

url:http://www.juniper.net/

Trust: 0.3

url:http://www.juniper.net/us/en/products-services/nos/junos/

Trust: 0.3

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10750&cat=sirt_1&actp=list

Trust: 0.3

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10750

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=47145

Trust: 0.1

url:https://threatpost.com/juniper-crypto-bug-lets-attackers-eavesdrop-on-router-switch-traffic/119319/

Trust: 0.1

sources: VULHUB: VHN-90094 // VULMON: CVE-2016-1275 // BID: 91758 // JVNDB: JVNDB-2016-004593 // CNNVD: CNNVD-201607-420 // NVD: CVE-2016-1275

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 91758

SOURCES

db:VULHUBid:VHN-90094
db:VULMONid:CVE-2016-1275
db:BIDid:91758
db:JVNDBid:JVNDB-2016-004593
db:CNNVDid:CNNVD-201607-420
db:NVDid:CVE-2016-1275

LAST UPDATE DATE

2025-04-13T23:29:28.325000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-90094date:2017-09-01T00:00:00
db:VULMONid:CVE-2016-1275date:2017-09-01T00:00:00
db:BIDid:91758date:2016-07-13T00:00:00
db:JVNDBid:JVNDB-2016-004593date:2016-09-12T00:00:00
db:CNNVDid:CNNVD-201607-420date:2016-09-12T00:00:00
db:NVDid:CVE-2016-1275date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-90094date:2016-09-09T00:00:00
db:VULMONid:CVE-2016-1275date:2016-09-09T00:00:00
db:BIDid:91758date:2016-07-13T00:00:00
db:JVNDBid:JVNDB-2016-004593date:2016-09-12T00:00:00
db:CNNVDid:CNNVD-201607-420date:2016-07-15T00:00:00
db:NVDid:CVE-2016-1275date:2016-09-09T14:05:02.297