CVE-2016-1264

Description

Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before 13.2X52-D30, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4, 15.1 before 15.1F2 or 15.1R2, 15.1X49 before 15.1X49-D10 or 15.1X49-D20, and 16.1 before 16.1R1 allows remote authenticated users to gain privileges via the URL option.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.807

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-1256,CVE-2016-1261,CVE-2016-1264,CVE-2016-1267 are fixed in junos 12.1x44-d55NCM
Multiple Vulnerabilities are fixed in junos 12.1x46-d40NCM
Multiple Vulnerabilities are fixed in junos 12.1x47-d25NCM
Multiple Vulnerabilities are fixed in junos 12.3r11NCM
Multiple Vulnerabilities are fixed in junos 13.2r8NCM
Multiple Vulnerabilities are fixed in junos 13.3r7NCM
Multiple Vulnerabilities are fixed in junos 14.1r6NCM
Multiple Vulnerabilities are fixed in junos 14.2r4NCM
Vulnerabilities CVE-2015-7751,CVE-2016-1264,CVE-2016-1267,CVE-2017-10601 are fixed in junos 15.1f2NCM
Vulnerabilities CVE-2016-1264,CVE-2016-1267,CVE-2016-1280 are fixed in junos 16.1r1NCM
CVE-2016-1264NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1
PATCH-1704488Security Update for junos 9.2r1

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234