6.8

CVE-2015-3006

Junos: QFX Series: Insufficient entropy on QFX3500 and QFX3600 platforms when the system boots up

On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 12.2x50 Update d10
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 12.2x50 Update d20
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 12.2x50 Update d41.1
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 12.2x50 Update d42.1
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 12.2x50 Update d56.1
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.1x50 Update d10
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.1x50 Update d25
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x51 Update d15
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x51 Update d20
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x51 Update d20.2
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x51 Update d21
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x52 Update d10
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 13.2x52 Update d5
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Juniper ≫ Junos Version 14.1x53 Update -
   Juniper ≫ Qfx3500 Version -
   Juniper ≫ Qfx3600 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.508
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 6.8 8 6.9
AV:N/AC:L/Au:S/C:C/I:N/A:N
MITRE 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.