On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://kb.juniper.net/JSA10678 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-28T22:26:33.894969Z
Updated: 2024-09-16T18:19:24.874Z
Reserved: 2015-04-07T00:00:00
Link: CVE-2015-3006
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-28T23:15:11.010
Modified: 2024-11-21T02:28:29.740
Link: CVE-2015-3006
Redhat
No data.