CVE-2016-1278 describes a critical vulnerability in Juniper Junos OS versions prior to 12.1X46-D50 on SRX Series devices. This flaw allows local users to gain root CLI access without a password if a system upgrade to 12.1X46 fails, causing the device to revert to "safe mode" authentication. With a CVSS score of 7.8 (High), this vulnerability presents a significant risk, as it enables privilege escalation through a low-complexity local attack, leading to high impacts on confidentiality, integrity, and availability. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.1x46CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:d45:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.