CVE-2016-1278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
05/08/2016
Last modified:
12/04/2025

Description

Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "request system software" command with the "partition" option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:junos:*:d45:*:*:*:*:*:* 12.1x46 (including)