Learn about CVE-2019-0015, a vulnerability in Junos OS on SRX Series devices allowing deleted dynamic VPN users to establish connections until reboot. Find out the impacted versions and mitigation steps.
A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted.
Understanding CVE-2019-0015
What is CVE-2019-0015?
This CVE identifies a flaw in Junos OS on SRX Series devices that permits deleted dynamic VPN users to reconnect until the device is rebooted.
The Impact of CVE-2019-0015
The vulnerability allows deleted users to establish VPN connections, posing a risk of unauthorized access until a reboot clears the cached authentication token.
Technical Details of CVE-2019-0015
Vulnerability Description
The issue arises from a token caching error, enabling deleted dynamic VPN users to reconnect after a successful connection until a reboot.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates