CVE-2016-1278
CVE-2016-1278 is a high-severity vulnerability in Juniper Junos with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- CVSS v2: 6.9
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Juniper Junos
- Published:
- Last modified:
Description
Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "request system software" command with the "partition" option.
Frequently asked questions
- What is CVE-2016-1278?
- Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "request system software" command with the "partition" option.
- How severe is CVE-2016-1278?
- CVE-2016-1278 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2016-1278 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-1278?
- CVE-2016-1278 affects Juniper Junos. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2016-1278?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2016-1278 published?
- CVE-2016-1278 was published on 2016-08-05 and last updated on 2026-06-17.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10753
- http://www.securityfocus.com/bid/91757
- http://www.securitytracker.com/id/1036307
Affected products (1)
- cpe:2.3:o:juniper:junos:*:d45:*:*:*:*:*:*
More vulnerabilities in Juniper Junos
- CVE-2021-0248 — Critical (CVSS 10.0): This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in…
- CVE-2021-0211 — Critical (CVSS 10.0): An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing…
- CVE-2020-1614 — Critical (CVSS 10.0): A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF)…
- CVE-2017-2343 — Critical (CVSS 10.0): The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series…
- CVE-2013-4685 — Critical (CVSS 10.0): Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44…
- CVE-2017-2349 — Critical (CVSS 9.9): A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially…
All CVEs affecting Juniper Junos →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →