CVE-2016-1276 describes a denial-of-service vulnerability affecting Juniper Junos OS on High-End SRX-Series chassis systems with Application Layer Gateways (ALGs) enabled. Remote attackers can exploit this by sending specific in-transit traffic that matches ALG rules, leading to high CPU consumption, fabric link failures, or flip-flop failovers. Rated Medium severity with a CVSS score of 5.9, the attack requires no user interaction and can be executed remotely, though with high attack complexity. The primary impact is a denial of service, compromising system availability. Currently, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:-:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:* | ||
12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.