First published: Fri Oct 13 2017(Updated: )
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | =12.1x46 | |
Juniper Junos | =12.1x46-d10 | |
Juniper Junos | =12.1x46-d15 | |
Juniper Junos | =12.1x46-d20 | |
Juniper Junos | =12.1x46-d25 | |
Juniper Junos | =12.1x46-d30 | |
Juniper Junos | =12.1x46-d35 | |
Juniper Junos | =12.1x46-d40 | |
Juniper Junos | =12.1x46-d45 | |
Juniper Junos | =12.1x46-d50 | |
Juniper Junos | =12.1x46-d55 | |
Juniper Junos | =12.1x46-d60 | |
Juniper Junos | =12.1x46-d65 | |
Juniper SRX100 | ||
Juniper SRX110 | ||
Juniper SRX1400 | ||
Juniper SRX1500 | ||
Juniper SRX210 | ||
Juniper SRX220 | ||
Juniper SRX240 | ||
Juniper SRX300 | ||
Juniper SRX320 | ||
Juniper SRX340 | ||
Juniper SRX3400 | ||
Juniper SRX345 | ||
Juniper SRX3600 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX5400 | ||
Juniper SRX550 | ||
Juniper SRX5600 | ||
Juniper SRX5800 | ||
Juniper SRX650 | ||
Juniper Junos | =12.3x48 | |
Juniper Junos | =12.3x48-d10 | |
Juniper Junos | =12.3x48-d15 | |
Juniper Junos | =12.3x48-d20 | |
Juniper Junos | =12.3x48-d25 | |
Juniper Junos | =12.3x48-d30 | |
Juniper Junos | =12.3x48-d35 | |
Juniper Junos | =12.3x48-d40 | |
Juniper Junos | =12.3x48-d45 | |
Juniper Junos | =12.3x48-d50 | |
Juniper Junos | =12.3x48-d55 | |
Juniper Junos | =15.1x49 | |
Juniper Junos | =15.1x49-d10 | |
Juniper Junos | =15.1x49-d100 | |
Juniper Junos | =15.1x49-d20 | |
Juniper Junos | =15.1x49-d30 | |
Juniper Junos | =15.1x49-d35 | |
Juniper Junos | =15.1x49-d40 | |
Juniper Junos | =15.1x49-d45 | |
Juniper Junos | =15.1x49-d50 | |
Juniper Junos | =15.1x49-d55 | |
Juniper Junos | =15.1x49-d60 | |
Juniper Junos | =15.1x49-d65 | |
Juniper Junos | =15.1x49-d70 | |
Juniper Junos | =15.1x49-d75 | |
Juniper Junos | =15.1x49-d80 | |
Juniper Junos | =15.1x49-d90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10620 has a medium severity because it allows man-in-the-middle attacks that can disrupt services.
To fix CVE-2017-10620, upgrade to a patched version of Junos OS that verifies HTTPS server certificates before downloading updates.
CVE-2017-10620 affects specific versions of Junos OS 12.1x46 and 12.3x48, along with various updates and patches.
CVE-2017-10620 could facilitate service disruptions or failure to detect certain types of attacks via injected bogus signatures.
CVE-2017-10620 is specific to Juniper Networks SRX series devices running the affected versions of Junos OS.