CVE-2019-0015
15.01.2019, 21:29
A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due to an error in token caching, deleted users are allowed to connect once a previously successful dynamic VPN connection has been established. A reboot is required to clear the cached authentication token. Affected releases are Junos OS on SRX Series: 12.3X48 versions prior to 12.3X48-D75; 15.1X49 versions prior to 15.1X49-D150; 17.3 versions prior to 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.Enginsight
Vendor | Product | Version |
---|---|---|
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 12.3x48:x48 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 15.1x49:x49 |
juniper | junos | 17.3 |
juniper | junos | 17.3:r1 |
juniper | junos | 17.3:r1-s1 |
juniper | junos | 17.3:r1-s4 |
juniper | junos | 17.3:r2 |
juniper | junos | 17.3:r2-s1 |
juniper | junos | 17.3:r2-s2 |
juniper | junos | 17.3:r2-s3 |
juniper | junos | 17.3:r2-s4 |
juniper | junos | 17.3:r2-s5 |
juniper | junos | 17.4 |
juniper | junos | 17.4:r1 |
juniper | junos | 17.4:r1-s1 |
juniper | junos | 17.4:r1-s2 |
juniper | junos | 17.4:r1-s3 |
juniper | junos | 17.4:r1-s4 |
juniper | junos | 17.4:r1-s5 |
juniper | junos | 17.4:r1-s6 |
juniper | junos | 17.4:r1-s7 |
juniper | junos | 18.1 |
juniper | junos | 18.1:r |
juniper | junos | 18.1:r1 |
juniper | junos | 18.1:r2 |
juniper | junos | 18.1:r2-s1 |
juniper | junos | 18.1:r2-s2 |
juniper | junos | 18.1:r2-s4 |
juniper | junos | 18.2 |
juniper | junos | 18.2:r |
juniper | junos | 18.2:r1 |
juniper | junos | 18.2:r1 |
juniper | junos | 18.2:r1-s2 |
juniper | junos | 18.2:r1-s3 |
juniper | junos | 18.2:r1-s4 |
juniper | junos | 18.2:r1-s5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration