Product Affected

Junos Space
High

Problem

Multiple vulnerabilities have been fixed in Juniper Networks Junos Space product as a result of updating Apache HTTP server to version 2.2.21.

The following is a list of known CVE ids that may pose a security risk to Junos Space, which have been fixed as a result of this software upgrade:

CVE Id CVSSv2 Base Score and CVSS Vector
CVE-2011-3348 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
CVE-2011-3192 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C
CVE-2011-0419 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P

CVE-2011-3192 with the highest CVSS score of 7.8 is a denial of service vulnerability with known exploits.

Solution

These vulnerabilities are fixed in Junos Space Patch 12.1P2.1 (released August 2012) or later versions.

Workaround


There are no known workarounds that can mitigate Apache HTTP server issues listed in this bulletin. Risk of malicious exploit can be reduced by limiting access to Junos Space only from trusted hosts by using access lists or firewall filters.

Severity Assessment

The highest CVSSv2 Base Score for these vulnerabilities is 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Related Information