CVE-2016-1270 Details
Description
The rpd daemon in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R6, 14.1 before 14.1R4, and 14.2 before 14.2R2, when configured with BGP-based L2VPN or VPLS, allows remote attackers to cause a denial of service (daemon restart) via a crafted L2VPN family BGP update.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10737 | CVE | Vendor Advisory |
| http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10737 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-19 | Data Processing Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | <= 12.1x44 12.1x46 12.1x46 d10 12.1x46 d15 12.1x46 d20 12.1x46 d25 12.1x46 d30 12.1x46 d35 12.1x46 d40 12.1x47 12.1x47 d10 12.1x47 d15 12.1x47 d20 12.1x47 d25 12.3 12.3 r1 12.3 r2 12.3 r3 12.3 r4 12.3 r5 12.3 r6 12.3 r7 12.3 r8 12.3x48 d10 12.3x48 d15 13.2 13.2 r1 13.2 r2 13.2 r3 13.2 r4 13.2 r5 13.2 r6 13.2x51 d15 13.2x51 d20 13.2x51 d21 13.2x51 d25 13.2x51 d26 13.2x51 d30 13.2x51 d35 13.3 13.3 r1 13.3 r2 13.3 r3 13.3 r4 13.3 r5 13.3 r6 14.1 14.1 r1 14.1 r2 14.1 r3 14.2 r1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 20, 2016 | Modified Analysis | [email protected] |
| Apr 19, 2016 | Initial Analysis | [email protected] |