CVE-2016-1268: Input Validation
Published Apr 15, 2016
·Updated
The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.
Affected Software
1 affected component
Juniper ScreenOS=6.3.0-r19
Event History
Apr 15, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1268?
CVE-2016-1268 is considered a high severity vulnerability due to the potential for remote attackers to remotely reboot affected systems.
2
How do I fix CVE-2016-1268?
To fix CVE-2016-1268, upgrade your Juniper ScreenOS to version 6.3.0r21 or later.
3
What type of attack is associated with CVE-2016-1268?
CVE-2016-1268 allows for a denial of service (DoS) attack via crafted SSL packets.
4
Which versions of Juniper ScreenOS are affected by CVE-2016-1268?
CVE-2016-1268 affects Juniper ScreenOS versions before 6.3.0r21, including 6.3.0r19.
5
Is there any workaround available for CVE-2016-1268?
There are no effective workarounds for CVE-2016-1268; the only way to mitigate the vulnerability is to upgrade to the patched version.