Unauthenticated access and information leakage Vulnerability (CVE-2015-7755)
Unauthenticated access and information leakage Vulnerability (CVE-2015-7755)
Release date:
Updated on:
Affected Systems:
Juniper Networks ScreenOS 6.3.0r20
Juniper Networks ScreenOS 6.3.0r19
Juniper Networks ScreenOS 6.3.0r18
Juniper Networks ScreenOS 6.3.0r17
Unaffected system:
Juniper Networks ScreenOS >= 6.3.0r21
Juniper Networks ScreenOS >= 6.2.0r19
Juniper Networks ScreenOS 6.3.0r19b
Juniper Networks ScreenOS 6.3.0r18b
Juniper Networks ScreenOS 6.3.0r17b
Juniper Networks ScreenOS 6.3.0r16b
Juniper Networks ScreenOS 6.3.0r15b
Juniper Networks ScreenOS 6.3.0r14b
Juniper Networks ScreenOS 6.3.0r13b
Juniper Networks ScreenOS 6.3.0r12b
Description:
Bugtraq id: 79626
CVE (CAN) ID: CVE-2015-7755
Juniper screnos is the operating system used by Juniper SSG and NetScreen Firewall Products.
Juniper screnos 6.2.0r15-6.2.0r18 and 6.3.0r12-6.3.0r20 have security vulnerabilities, which allow remote attackers to access affected devices with administrator privileges in SSH or telnet sessions, after successful exploitation, the affected system can be controlled.
<* Source: vendor
Link: http://kb.juniper.net/InfoCenter/index? Page = content & id = jsa31613 & actp = search
*>
Suggestion:
Vendor patch:
Juniper Networks
----------------
Juniper Networks has released a Security Bulletin (jsa51113) and corresponding patches for this:
Jsa31613: screnos: Multiple Security issues with screnos (CVE-2015-7755, CVE-2015-7756)
Link: http://kb.juniper.net/InfoCenter/index? Page = content & id = jsa31613 & actp = search
Patch download: http://www.juniper.net/support/downloads/screenos.html
Refer:
Https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554
Http://forums.juniper.net/t5/Security-Incident-Response/bg-p/SIRT
This article permanently updates the link address: