CVE-2016-1275 describes a vulnerability in Juniper Junos OS versions prior to 13.3R9, 14.1R6-S1, and 14.1R7, specifically when configured with VPLS routing-instances. Remote attackers can exploit this by injecting a flood of Ethernet frames with IPv6 MAC addresses into a connected interface, leading to the disclosure of sensitive mbuf information. The vulnerability has a CVSS v3 score of 6.5 (MEDIUM), indicating an attack vector of adjacent network, low attack complexity, and high availability impact, though confidentiality and integrity are not affected. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond an initial SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.3CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:r8:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:*:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:r1:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:r2:*:*:*:*:*:* | ||
14.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:14.1:r3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.