| Vulnerability Name: | CVE-2015-7756 (CCN-109110) | ||||||||
| Assigned: | 2015-12-19 | ||||||||
| Published: | 2015-12-19 | ||||||||
| Updated: | 2016-12-07 | ||||||||
| Summary: | The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-310 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MISC Type: UNKNOWN http://arstechnica.com/security/2015/12/unauthorized-code-in-juniper-firewalls-decrypts-encrypted-vpn-traffic/ Source: MITRE Type: CNA CVE-2015-7756 Source: CCN Type: Juniper Networks Security Bulletin JSA10713 2015-12 Out of Cycle Security Bulletin: ScreenOS: Multiple Security issues with ScreenOS (CVE-2015-7755, CVE-2015-7756) Source: CONFIRM Type: Vendor Advisory http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713 Source: MISC Type: UNKNOWN http://www.forbes.com/sites/thomasbrewster/2015/12/18/juniper-says-it-didnt-work-with-government-to-add-unauthorized-code-to-network-gear/ Source: CCN Type: US-CERT VU#640184 Juniper ScreenOS contains multiple vulnerabilities Source: CERT-VN Type: UNKNOWN VU#640184 Source: SECTRACK Type: UNKNOWN 1034489 Source: MISC Type: UNKNOWN http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/ Source: MISC Type: UNKNOWN https://adamcaudill.com/2015/12/17/much-ado-about-juniper/ Source: XF Type: UNKNOWN juniper-screenos-cve20157756-info-disc(109110) Source: CONFIRM Type: UNKNOWN https://forums.juniper.net/t5/Security-Incident-Response/Important-Announcement-about-ScreenOS/ba-p/285554 Source: MISC Type: UNKNOWN https://github.com/hdm/juniper-cve-2015-7755 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||