CVE-2019-0054: Junos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.
An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which may compromise the integrity and confidentiality of the device. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D120 on SRX Series devices. No other versions of Junos OS are affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-0054?
CVE-2019-0054 is an Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS.
What is the severity of CVE-2019-0054?
The severity of CVE-2019-0054 is high with a CVSS score of 7.4.
How does CVE-2019-0054 affect Juniper JUNOS?
CVE-2019-0054 affects Juniper JUNOS versions 15.1x49-d10 to 15.1x49-d90.
What are the potential impacts of CVE-2019-0054?
CVE-2019-0054 may compromise the integrity and confidentiality of the device and allow Man-in-the-Middle (MitM) attacks.
Where can I find more information about CVE-2019-0054?
You can find more information about CVE-2019-0054 in the Juniper Networks knowledge base article JSA10952 and the Juniper Networks Junos OS documentation on security and application identification.