CVE-2016-1276

Published on: 08/05/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:04 PM UTC

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Junos from Juniper contain the following vulnerability:

Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause a denial of service (CPU consumption, fab link failure, or flip-flop failovers) via vectors related to in-transit traffic matching ALG rules.

  • CVE-2016-1276 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.9 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 7.1 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE COMPLETE

CVE References

Description Tags Link
Juniper Junos High-End SRX-Series Application Layer Gateway Bugs Lets Remote Users Deny Service - SecurityTracker Third Party Advisory
VDB Entry
www.securitytracker.com
text/html
URL Logo SECTRACK 1036305
Juniper Junos CVE-2016-1276 Multiple Denial of Service Vulnerabilities Third Party Advisory
VDB Entry
cve.report (archive)
text/html
URL Logo BID 91764
2016-07 Security Bulletin: SRX Series: On High-End SRX-Series, ALG’s applied to in-transit traffic may trigger high CP (central point) utilization leading to denial of services. (CVE-2016-1276) - Juniper Networks Mitigation
Vendor Advisory
kb.juniper.net
text/html
URL Logo CONFIRM kb.juniper.net/InfoCenter/index?page=content&id=JSA10751

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
JuniperJunos12.1x46-AllAll
Operating
System
JuniperJunos12.1x46d10AllAll
Operating
System
JuniperJunos12.1x46d15AllAll
Operating
System
JuniperJunos12.1x46d20AllAll
Operating
System
JuniperJunos12.1x46d25AllAll
Operating
System
JuniperJunos12.1x46d30AllAll
Operating
System
JuniperJunos12.1x46d35AllAll
Operating
System
JuniperJunos12.1x46d40AllAll
Operating
System
JuniperJunos12.1x46d45AllAll
Operating
System
JuniperJunos12.1x47-AllAll
Operating
System
JuniperJunos12.1x47d10AllAll
Operating
System
JuniperJunos12.1x47d15AllAll
Operating
System
JuniperJunos12.1x47d20AllAll
Operating
System
JuniperJunos12.3x48d10AllAll
Operating
System
JuniperJunos12.3x48d15AllAll
Operating
System
JuniperJunos15.1x49d10AllAll
Operating
System
JuniperJunos15.1x49d150AllAll
Operating
System
JuniperJunos15.1x49d20AllAll
Operating
System
JuniperJunos15.1x49d30AllAll
Operating
System
JuniperJunos15.1x49d35AllAll
Operating
System
JuniperJunos12.1x46-AllAll
Operating
System
JuniperJunos12.1x46d10AllAll
Operating
System
JuniperJunos12.1x46d15AllAll
Operating
System
JuniperJunos12.1x46d20AllAll
Operating
System
JuniperJunos12.1x46d25AllAll
Operating
System
JuniperJunos12.1x46d30AllAll
Operating
System
JuniperJunos12.1x46d35AllAll
Operating
System
JuniperJunos12.1x46d40AllAll
Operating
System
JuniperJunos12.1x46d45AllAll
Operating
System
JuniperJunos12.1x47-AllAll
Operating
System
JuniperJunos12.1x47d10AllAll
Operating
System
JuniperJunos12.1x47d15AllAll
Operating
System
JuniperJunos12.1x47d20AllAll
Operating
System
JuniperJunos12.3x48d10AllAll
Operating
System
JuniperJunos12.3x48d15AllAll
Operating
System
JuniperJunos15.1x49d10AllAll
Operating
System
JuniperJunos15.1x49d150AllAll
Operating
System
JuniperJunos15.1x49d20AllAll
Operating
System
JuniperJunos15.1x49d30AllAll
Operating
System
JuniperJunos15.1x49d35AllAll
  • cpe:2.3:o:juniper:junos:12.1x46:-:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d30:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d35:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d40:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d45:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:-:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d150:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:-:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d30:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d35:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d40:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x46:d45:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:-:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.1x47:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d150:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:*:
  • cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:*: