Product Affected

IVE: SA 500, SA 700, SA 1000, SA 2000, SA 2500, SA 3000, SA 4000, SA 4500, SA 5000, SA 6000, SA 6500, SA 3000 FIPS, SA 4000 FIPS, SA 4500 FIPS, SA 5000 FIPS, SA 6000 FIPS, SA 6500 FIPS IC: IC4000, IC4500, IC6000, IC6500, IC6500 FIPS
Medium
5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)

Problem

SA and UAC use ActiveX controls or Java applets to install and launch client software from a web browser. Due to the inherent problems with using ActiveX and Java applet, users can unknowingly connect to untrusted/rogue SA and UAC and components can be launched without their knowledge.

Solution

The Trusted Server List (also known as allowlist) is a new feature added to address the issue.

Due to the behavioral change and impact of the end user environment, Juniper has added this feature in 6.5 IVE OS release and higher and UAC 3.1 release and higher.

Information regarding the Juniper Network fix policy for Security Issues can be found at KB16765 [juniper.net] "In which releases are vulnerabilities fixed?"
 

Workaround

None

Severity Assessment

- User can unknowingly connect to a rogue SA or IC.Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2010-06-09: Initial Publication
2020-11-06: Updated terminology

Related Information