Certain versions of NSM products are supplied with a default self-signed certificate containing both public and private components. The certificate is identical across multiple installations of the product and software releases. In later versions, the key pair is used to encrypt TLS traffic between NSM client and NSM server, and thus the knowledge of the key pair can make it possible for an attacker to decrypt the traffic between the client and server if the attacker has access to the encrypted traffic. The decrypted traffic may include the user name and password for the administrative account, thus possibly leading to a complete compromise of the victim's NSM product. Juniper Networks began including self-signed certificates, by default, in NSM software with version 2007.3. Through version 2008.1, the certificate was only used for instantiation of a local proxy web server and the same certificate was distributed with all copies of the software distribution. Beginning with version 2008.2, NSM uses TLS with the installed certificate to protect the administrative connection between client and server. If the certificate has not been replaced by the customer, then the TLS traffic is protected with the same self-signed certificate provided by default to all other customers using the same version of NSM software. All subsequent releases of NSM software contain self-signed certificates and, if they have not been replaced, they are used with TLS to protect sensitive administrative traffic between NSM client and NSM server.
There is no fixed software for this issue. The threat can be completely mitigated by replacing the default self-signed certificates provided by Juniper Networks with:
The issue can be resolved by replacing the self-signed certificate provided in the NSM software distribution, preferably with a commercially-provided certificate from a recognized, established Certificate Authority. If that is not feasible or practical, a self-signed certificate signed by the customer can be generated by following the instructions in KB 14949 [juniper.net] and installing it in place of the default Juniper Networks self-signed certificate. Please refer to the Related Links section below for additional KB articles regarding this topic.