CVE-2015-3007: Juniper Junos

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

Affected products

  • Juniper Junos: version 12.1x46 only; version 12.1x47 only; version 12.3x48 only

Published 2015-07-14. Last modified 2026-06-17.