// For flags

CVE-2015-3006

Junos: QFX Series: Insufficient entropy on QFX3500 and QFX3600 platforms when the system boots up

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.

En las plataformas QFX3500 y QFX3600, el número de bytes recopilados desde la fuente de entropía de RANDOM_INTERRUPT cuando los arranques del dispositivo son insuficientes, conllevando posiblemente a claves SSH débiles o duplicadas o a certificados SSL/TLS auto-firmados. La entropía aumenta después que el sistema ha estado funcionando durante algún tiempo, pero inmediatamente después del arranque, la entropía es muy lenta. Este problema sólo afecta a los switches QFX3500 y QFX3600. Ningún otro producto o plataforma de Juniper Networks está afectada por esta vulnerabilidad de debilidad de la entropía.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-04-07 CVE Reserved
  • 2020-02-28 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-331: Insufficient Entropy
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://kb.juniper.net/JSA10678 2020-03-10
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d20
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d20
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d41.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d41.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d42.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d42.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d56.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.2x50
Search vendor "Juniper" for product "Junos" and version "12.2x50"
d56.1
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.1x50
Search vendor "Juniper" for product "Junos" and version "13.1x50"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.1x50
Search vendor "Juniper" for product "Junos" and version "13.1x50"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.1x50
Search vendor "Juniper" for product "Junos" and version "13.1x50"
d25
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.1x50
Search vendor "Juniper" for product "Junos" and version "13.1x50"
d25
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d15
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d15
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d20
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d20
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d20.2
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d20.2
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d21
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x51
Search vendor "Juniper" for product "Junos" and version "13.2x51"
d21
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x52
Search vendor "Juniper" for product "Junos" and version "13.2x52"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x52
Search vendor "Juniper" for product "Junos" and version "13.2x52"
d10
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x52
Search vendor "Juniper" for product "Junos" and version "13.2x52"
d5
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
13.2x52
Search vendor "Juniper" for product "Junos" and version "13.2x52"
d5
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
-
Affected
in Juniper
Search vendor "Juniper"
Qfx3500
Search vendor "Juniper" for product "Qfx3500"
--
Safe
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
-
Affected
in Juniper
Search vendor "Juniper"
Qfx3600
Search vendor "Juniper" for product "Qfx3600"
--
Safe