CVE-2015-5363: Medium severity junos os evolved vulnerability
Published Jul 16, 2015
·Updated
The SRX Network Security Daemon (nsd) in Juniper SRX Series services gateways with Junos 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 allows remote DNS servers to cause a denial of service (crash) via a crafted DNS response.
Affected Software
35 affected components
Juniper Junos=12.1x44
Juniper Junos=12.1x44-d10
Juniper Junos=12.1x44-d15
Juniper Junos=12.1x44-d20
Juniper Junos=12.1x44-d25
Juniper Junos=12.1x44-d30
Juniper Junos=12.1x44-d35
Juniper Junos=12.1x44-d40
Juniper Junos=12.1x44-d45
Juniper Junos=12.1x46
Juniper Junos=12.1x46-d10
Juniper Junos=12.1x46-d15
Juniper Junos=12.1x46-d20
Juniper Junos=12.1x46-d25
Juniper Junos=12.1x46-d30
Juniper Junos=12.1x47
Juniper Junos=12.1x47-d10
Juniper Junos=12.1x47-d15
Juniper Junos=12.1x47-d20
Juniper Junos=12.3x48
Juniper Junos=12.3x48-d10
Juniper Junos=12.3x48-d5
Juniper SRX100
Juniper SRX110
Juniper SRX1400
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper SRX3400
Juniper SRX3600
Juniper SRX5400
Juniper SRX550
Juniper SRX5600
Juniper SRX5800
Juniper SRX650
Event History
Jul 16, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5363?
CVE-2015-5363 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-5363?
To patch CVE-2015-5363, update your Junos software to the latest version recommended by Juniper.
3
Which versions of Junos are affected by CVE-2015-5363?
CVE-2015-5363 affects Junos versions prior to 12.1X44-D50, 12.1X46-D35, 12.1X47-D25, and 12.3X48-D15.
4
Can CVE-2015-5363 be exploited remotely?
Yes, CVE-2015-5363 can be exploited by remote DNS servers through crafted DNS responses.
5
What devices are impacted by CVE-2015-5363?
CVE-2015-5363 impacts Juniper SRX Series services gateways running vulnerable versions of Junos.