6.8

CVE-2015-3006

On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version12.2x50 Updated10
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version12.2x50 Updated20
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version12.2x50 Updated41.1
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version12.2x50 Updated42.1
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version12.2x50 Updated56.1
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.1x50 Updated10
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.1x50 Updated25
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x51 Updated15
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x51 Updated20
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x51 Updated20.2
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x51 Updated21
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x52 Updated10
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version13.2x52 Updated5
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
JuniperJunos Version14.1x53 Update-
   JuniperQfx3500 Version-
   JuniperQfx3600 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.322
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:C/I:N/A:N
cve@mitre.org 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.