A simple UNIX shell script can be used to exploit a vulnerability on a Juniper Networks Security Threat Response Manager (STRM) appliance and gain root access to the appliance without authentication. The only requirement is unrestricted Internet-Protocol (IP) connectivity to the appliance.
All software releases built on or after 2009-06-30 contain the fix for this vulnerability. Releases containing the fix specifically include 2008.3 patch 518, all 2009.* versions, and all subsequent releases. This issue is being tracked as "STRM PR 6488". Although it cannot be viewed by customers, the PR label can be used as a reference when discussing the issue with JTAC. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our "End of Engineering" and "End of Life" support policies.
No workarounds have been identified for this vulnerability. Upgrading to a fixed version of software is strongly recommended.