CVE-2016-1274: High severity junos os evolved vulnerability
Published Apr 15, 2016
·Updated
Juniper Junos OS 14.1X53 before 14.1X53-D30 on QFX Series switches allows remote attackers to cause a denial of service (PFE panic) via a high rate of unspecified VXLAN packets.
Affected Software
11 affected components
Juniper Junos=14.1x53
Juniper Junos=14.1x53-d10
Juniper Junos=14.1x53-d15
Juniper Junos=14.1x53-d16
Juniper Junos=14.1x53-d25
Juniper Junos=14.1x53-d26
Juniper QFX10000
Juniper QFX3500
Juniper QFX3600
Juniper QFX5100
Juniper QFX5200
Event History
Apr 15, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1274?
CVE-2016-1274 has a high severity rating due to its potential to cause a denial of service on affected Juniper devices.
2
How do I fix CVE-2016-1274?
To fix CVE-2016-1274, you should upgrade to Junos OS version 14.1X53-D30 or later.
3
Which devices are affected by CVE-2016-1274?
CVE-2016-1274 affects Juniper Junos OS versions 14.1X53 and its various updates prior to 14.1X53-D30.
4
What type of attack does CVE-2016-1274 allow?
CVE-2016-1274 allows remote attackers to initiate a denial of service attack through a high rate of VXLAN packets.
5
What are VXLAN packets in the context of CVE-2016-1274?
In the context of CVE-2016-1274, VXLAN packets are encapsulated Ethernet frames that can be exploited to trigger the denial of service condition.