CVE-2016-1262

Published on: 01/15/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:05 PM UTC

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Junos from Juniper contain the following vulnerability:

Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet.

  • CVE-2016-1262 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.9 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 4.3 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE PARTIAL

CVE References

Description Tags Link
Juniper Networks - 2016-01: Security Bulletin: Junos: SRX-Series denial of service vulnerability in flowd due to crafted RTSP packets (​​CVE-2016-1262) - Knowledge Base Vendor Advisory
kb.juniper.net
text/html
URL Logo CONFIRM kb.juniper.net/InfoCenter/index?page=content&id=JSA10721
Juniper SRX-Series Junos RTSP Processing Flaw Lets Remote Users Cause the Target Service to Crash - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1035108

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
JuniperJunos12.1x47AllAllAll
Operating
System
JuniperJunos12.1x47d10AllAll
Operating
System
JuniperJunos12.1x47d15AllAll
Operating
System
JuniperJunos12.1x47d20AllAll
Operating
System
JuniperJunos12.3x48d10AllAll
Operating
System
JuniperJunos12.3x48d15AllAll
Operating
System
JuniperJunos15.1x49d10AllAll
Operating
System
JuniperJunos15.1x49d20AllAll
Operating
System
JuniperJunos12.1x47AllAllAll
Operating
System
JuniperJunos12.1x47d10AllAll
Operating
System
JuniperJunos12.1x47d15AllAll
Operating
System
JuniperJunos12.1x47d20AllAll
Operating
System
JuniperJunos12.3x48d10AllAll
Operating
System
JuniperJunos12.3x48d15AllAll
Operating
System
JuniperJunos15.1x49d10AllAll
Operating
System
JuniperJunos15.1x49d20AllAll
Operating
System
JuniperJunosAlld40AllAll
  • cpe:2.3:o:juniper:junos:12.1x47:*:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:*:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:*:d40:*:*:*:*:*:*: