CVE-2015-3006: Junos: QFX Series: Insufficient entropy on QFX3500 and QFX3600 platforms when the system boots up
On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOMINTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2015-3006?
CVE-2015-3006 is a vulnerability found on the QFX3500 and QFX3600 platforms that leads to weak or duplicate SSH keys or self-signed SSL/TLS certificates due to insufficient entropy.
Which platforms are affected by CVE-2015-3006?
CVE-2015-3006 affects the QFX3500 and QFX3600 platforms.
How does CVE-2015-3006 impact the affected platforms?
CVE-2015-3006 can result in the generation of weak or duplicate SSH keys or self-signed SSL/TLS certificates.
What is the severity of CVE-2015-3006?
CVE-2015-3006 has a severity rating of 6.5, considered medium.
Where can I find more information about CVE-2015-3006?
More information about CVE-2015-3006 can be found at the Juniper Networks Knowledge Base: https://kb.juniper.net/JSA10678