CVE-2015-3002: Juniper Junos
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stanza, which allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device.
Affected products
- Juniper Junos: version 12.1x44 only; version 12.1x45 only; version 12.1x46 only; version 12.1x47 only; version 12.1x48 only
Published 2015-04-10. Last modified 2026-06-17.