Juniper fixes 30+ vulnerabilities in its routing, switching devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-0052 | If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. However, an undocumented CLI command allows a privileged Junos user to enable RSH service and disable PAM, and hence expose the system to unauthenticated root access. When RSH is enabled, the device is listing to RSH connections on port 514. This issue is not exploitable on platforms where Junos release is based on FreeBSD 10+. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on QFX/EX Series; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D131, 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 16.1 versions prior to 16.1R3-S9, 16.1R4-S9, 16.1R5-S4, 16.1R6-S4, 16.1R7; 16.2 versions prior to 16.2R2-S5; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S4, 17.2R3; 17.2X75 versions prior to 17.2X75-D110, 17.2X75-D91; 17.3 versions prior to 17.3R1-S4, 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S3, 17.4R2; 18.2X75 versions prior to 18.2X75-D5. NVD description · AI analysis pending | 8.1 group max | 5% |
| — | ||
| CVE-2018-0047 | A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2018-7183 | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. NVD description · AI analysis pending | 9.8 | 10% |
| — |
Full article394 words · extracted from helpnetsecurity.com · click to collapse
Juniper Networks has issued fixes for over thirty vulnerabilities affecting its routing, switching and security products running Junos OS.

Critical issues fixed
CVE-2018-0044 is an insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices, which may allow remote unauthenticated access if any of the passwords on the system are empty.
If users can’t update to version 18.1R4 (and later), which set the PermitEmptyPasswords option to no by default, they can either make sure that all the accounts are configured with a password or change the aforementioned option to no.
Juniper has also fixed six CVE-numbered vulnerabilities in ntpd (NTP daemon), most of which can cause a DoS condition.
CVE-2018-7183 is the most critical of the batch – a buffer overflow that could allow remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. To plug these holes, users can update the OS or implement an array of security best practices that can protect against any remote malicious attacks against NTP (they should do the latter anyway).
High risk vulnerabilities
Of the high risk issues fixed, some deserve to be singled out.
CVE-2018-0049 can lead to a Junos OS kernel to crash and, therefore, Denial of Service, if the device receives a specifically crafted malicious MPLS packet on an interface configured to receive this type of traffic. Continued receipt of such a packet will cause a sustained Denial of Service condition.
“Juniper SIRT is aware of possible malicious network probing which may have triggered this issue, but not aware of any malicious exploitation of this vulnerability,” the company noted.
CVE-2018-0047 is a XSS vulnerability in the UI framework used by Junos Space Security Director that may allow authenticated users to inject persistent and malicious scripts.
CVE-2018-0052 allows unauthenticated remote root access to a vulnerable device only if the RSH service is enabled and the PAM authentication disabled.
“RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. However, an undocumented CLI command allows a privileged Junos user to enable RSH service and disable PAM, and hence expose the system to unauthenticated root access. When RSH is enabled, the device is listing to RSH connections on port 514,” the company explained. The fixed version of the software removes the undocumented CLI option.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/10/11/juniper-vulnerabilities/