CVE-2016-1257

MEDIUM

Juniper Junos OS Multiple Versions - Denial of Service via Crafted LDP Packet

Title source: llm
STIX 2.1

Description

The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1R3-S9, 14.1R4 before 14.1R4-S7, 14.1X51 before 14.1X51-D65, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D28, 14.1X53 before 4.1X53-D35, 14.2R1 before 14.2R5, 14.2R3 before 14.2R3-S4, 14.2R4 before 14.2R4-S1, 15.1 before 15.1R3, 15.1F2 before 15.1F2-S2, and 15.1X49 before 15.1X49-D40, when LDP is enabled, allows remote attackers to cause a denial of service (RPD routing process crash) via a crafted LDP packet.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035117

Scores

CVSS v3 5.9
EPSS 0.0061
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (8)
juniper/junos 13.2 r5 (5 CPE variants)
juniper/junos 13.3 r1 (7 CPE variants)
juniper/junos 14.1 r1 (5 CPE variants)
juniper/junos 14.1x51 (2 CPE variants)
juniper/junos 14.1x53 (5 CPE variants)
juniper/junos 14.2 r1 (4 CPE variants)
juniper/junos 15.1 (5 CPE variants)
juniper/junos 15.1x49 d10 (2 CPE variants)
Published Jan 15, 2016
Tracked Since Feb 18, 2026