CVE-2016-1278

HIGH

Juniper Junos OS <12.1X46-D50 - Privilege Escalation

Title source: llm

Description

Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "request system software" command with the "partition" option.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-287
Status draft

Affected Products (1)

juniper/junos < 12.1x46

Timeline

Published Aug 05, 2016
Tracked Since Feb 18, 2026