First published: Wed Jul 11 2018(Updated: )
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the initial HTTP/HTTPS session is at risk that these credentials may be captured during follow-on HTTP/HTTPS requests by a malicious actor through a man-in-the-middle attack or by authentic servers subverted by malicious actors. FTP, and Telnet pass-through authentication services are not affected. Affected releases are Juniper Networks SRX Series: 12.1X46 versions prior to 12.1X46-D67 on SRX Series; 12.3X48 versions prior to 12.3X48-D25 on SRX Series; 15.1X49 versions prior to 15.1X49-D35 on SRX Series.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =12.1x46 | |
Juniper JUNOS | =12.1x46-d10 | |
Juniper JUNOS | =12.1x46-d15 | |
Juniper JUNOS | =12.1x46-d20 | |
Juniper JUNOS | =12.1x46-d25 | |
Juniper JUNOS | =12.1x46-d30 | |
Juniper JUNOS | =12.1x46-d35 | |
Juniper JUNOS | =12.1x46-d40 | |
Juniper JUNOS | =12.1x46-d45 | |
Juniper JUNOS | =12.1x46-d50 | |
Juniper JUNOS | =12.1x46-d55 | |
Juniper JUNOS | =12.1x46-d60 | |
Juniper JUNOS | =12.1x46-d65 | |
Juniper JUNOS | =12.1x46-d66 | |
Juniper SRX100 | ||
Juniper SRX110 | ||
Juniper SRX1400 | ||
Juniper SRX1500 | ||
Juniper SRX210 | ||
Juniper SRX220 | ||
Juniper SRX240 | ||
Juniper SRX300 | ||
Juniper SRX320 | ||
Juniper SRX340 | ||
Juniper SRX3400 | ||
Juniper SRX345 | ||
Juniper SRX3600 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX5400 | ||
Juniper SRX550 | ||
juniper srx5600 | ||
Juniper SRX5800 | ||
Juniper SRX650 | ||
Juniper JUNOS | =12.3x48 | |
Juniper JUNOS | =12.3x48-d10 | |
Juniper JUNOS | =12.3x48-d15 | |
Juniper JUNOS | =12.3x48-d20 | |
Juniper JUNOS | =15.1x49 | |
Juniper JUNOS | =15.1x49-d10 | |
Juniper JUNOS | =15.1x49-d20 | |
Juniper JUNOS | =15.1x49-d30 |
The following software releases have been updated to resolve this specific issue: Junos OS:12.1X46-D67, 12.3X48-D25, 15.1X49-D35, 17.3R1 all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0025 is classified as a high severity vulnerability due to the potential exposure of sensitive authentication credentials.
To fix CVE-2018-0025, update affected Juniper JUNOS versions to the latest available release that addresses this vulnerability.
CVE-2018-0025 affects several versions of Juniper JUNOS, specifically 12.1x46 and 12.3x48 for various SRX Series devices.
The implications of CVE-2018-0025 include potential interception of authentication credentials by attackers during HTTP/HTTPS sessions.
Yes, CVE-2018-0025 can be exploited remotely if the device is vulnerable and configured to use HTTP/HTTPS pass-through authentication.