Product Affected

Steel-Belted Radius v5.3.2 (MIM [Mobile IP Module]) Steel-Belted Radius v5.4.0 (Enterprise, Global Enterprise, Service Provider, and SIM Server Editions) Steel-Belted Radius v5.4.1 (Enterprise, Global Enterprise, and Service Provider Editions) Steel-Belted Radius v5.5.0 (HA [High Availability] Edition) Steel-Belted Radius v6.0.1 (Enterprise, Global Enterprise, and Service Provider Editions) Steel-Belted Radius v6.1.0 (Enterprise, Global Enterprise, and Service Provider Editions)
High

Problem

By sending crafted, invalid data to the TCP administration port (1813 by default) or the TCP control port (1812 by default) an attacker may be able to crash the SBR server process. An attacker may also be able to inject code that will run as root on the server machine.

If firewalls or other measures in your enterprise protect these ports well enough, then this vulnerability may not be serious for you.

This issue affects all versions of SBR built prior to July 31, 2008 running on Linux or Solaris platforms. Versions of SBR running on Windows platforms are not affected.

Solution

Juniper has created a patch for each affected version.

Please see the attached document for instructions on installing the patches.

Severity Assessment

This vulnerability is a remotely exploitable Denial of Service and hijack. An attacker requires no logon access or other privileges on the Steel-Belted Radius server.

Modification History

Modification History:

2017-03-05: Category restructure.