Product Affected

This is a "zero day" issue which affects all STRM appliances running a vulnerable version of software.
Critical
9.0 (AV:N/AC:M/Au:N/C:P/I:C/A:C/E:F/RL:U/RC:C)

Problem

A simple UNIX shell script can be used to exploit a vulnerability on a Juniper Networks Security Threat Response Manager (STRM) appliance and gain root access to the appliance without authentication. The only requirement is unrestricted Internet-Protocol (IP) connectivity to the appliance.

Solution

All software releases built on or after 2009-06-30 contain the fix for this vulnerability. Releases containing the fix specifically include 2008.3 patch 518, all 2009.* versions, and all subsequent releases.

This issue is being tracked as "STRM PR 6488". Although it cannot be viewed by customers, the PR label can be used as a reference when discussing the issue with JTAC.

KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our "End of Engineering" and "End of Life" support policies.


How To Obtain Fixed Software:
STRM Maintenance Releases and Patches are available at http://support.juniper.net from the "Download Software" links.

Workaround

No workarounds have been identified for this vulnerability. Upgrading to a fixed version of software is strongly recommended.

Severity Assessment

Information regarding how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories".

Related Information