First published: Fri Apr 15 2016(Updated: )
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | <=13.2x51 | |
Juniper Junos | =14.1x53 | |
Juniper Junos | =14.1x53-d10 | |
Juniper Junos | =14.1x53-d15 | |
Juniper Junos | =14.1x53-d16 | |
Juniper Junos | =14.1x53-d25 | |
Juniper Junos | =14.1x53-d26 | |
Juniper Junos | =15.1-f2 | |
Juniper Junos | =15.1-f2-s1 | |
Juniper Junos | =15.1-r1 | |
Juniper Junos | =15.1-r2 | |
Juniper Junos | =15.1x49-d10 | |
Juniper Junos | =15.1x49-d20 | |
Juniper Junos | =15.1x53-d10 | |
Juniper QFX10002-60C | ||
Juniper QFX5100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1273 is considered a high severity vulnerability due to insufficient entropy affecting cryptographic mechanisms.
To remediate CVE-2016-1273, you should update the Junos OS to a version that is not affected, specifically versions after 13.2X51-D40, 14.1X53-D30, and 15.1X53-D20.
CVE-2016-1273 affects Juniper QFX5100 and QFX10002 switches running vulnerable versions of Junos OS.
Exploitation of CVE-2016-1273 can allow remote attackers to weaken cryptographic encryption and authentication protections.
CVE-2016-1273 pertains to a vulnerability that arises from insufficient entropy in the Junos OS.