Product Affected

Network and Security Manager NSM3000 NSMXpress/NSMXpress HA
Critical

Problem

Multiple vulnerabilities have been fixed in Juniper Networks NSM products (NSMXpress, NSMXpress II, NSM3000, and NSMserver) as a result of upgrading base operating system to CentOS 5.7 on NSM Appliances and RedHat EL 5.7 on software NSM installations.

Following is a list of known CVE ids that may pose a security risk to NSM products, which have been fixed as a result of this software upgrade:

Component CVE CVSSv2
base
score
CVSSv2 Vector
Apache APR-util CVE-2009-0023 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
CVE-2009-1955 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C
CVE-2009-1956 6.4 AV:N/AC:L/Au:N/C:P/I:N/A:P
CVE-2009-2412 10 AV:N/AC:L/Au:N/C:C/I:C/A:C
CVE-2010-1623 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2011-0419 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
ISC BIND CVE-2007-2926 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N
CVE-2011-2464 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
Linux Kernel CVE-2011-1162 2.1 AV:L/AC:L/Au:N/C:P/I:N/A:N
CVE-2011-2203 2.1 AV:L/AC:L/Au:N/C:N/I:N/A:P
CVE-2011-2484 4.9 AV:L/AC:L/Au:N/C:N/I:N/A:C
CVE-2011-2494 2.1 AV:L/AC:L/Au:N/C:P/I:N/A:N
CVE-2011-2695 4.9 AV:L/AC:L/Au:N/C:N/I:N/A:C
CVE-2011-2723 5.7 AV:A/AC:M/Au:N/C:N/I:N/A:C
CVE-2011-4110 2.1 AV:L/AC:L/Au:N/C:N/I:N/A:P
libxml2 CVE-2010-4008 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
CVE-2011-1944 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C
CVE-2011-2834 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P
CVE-2011-3905 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2011-3919 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P
OpenSSL CVE-2009-0590 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-1377 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-1378 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-1379 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-1386 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-1387 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-3245 10 AV:N/AC:L/Au:N/C:C/I:C/A:C
CVE-2009-3555 5.8 AV:N/AC:M/Au:N/C:N/I:P/A:P
CVE-2009-4355 5 AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2010-0433 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
CVE-2010-4180 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N
PHP CVE-2007-3996 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P
PostgreSQL CVE-2006-5540 4 AV:N/AC:L/Au:S/C:N/I:N/A:P
CVE-2006-5541 4 AV:N/AC:L/Au:S/C:N/I:N/A:P
CVE-2006-5542 4 AV:N/AC:L/Au:S/C:N/I:N/A:P
CVE-2007-0555 8.5 AV:N/AC:L/Au:S/C:C/I:N/A:C
CVE-2007-0556 6.6 AV:N/AC:H/Au:S/C:C/I:N/A:C
CVE-2010-4015 6.5 AV:N/AC:L/Au:S/C:P/I:P/A:P

These issues were discovered in a variety of ways, and all are known publicly.

Please refer to NSM release notes for a complete list of CVEs that were fixed.

Solution

These vulnerabilities are fixed in:
NSM version 2012.1 and later
NSM version 2011.4s4 and later
NSM version 2010.3s7 and later

Note CentOS or RedHat version should also be upgraded to 5.7.
CentOS 5.7 upgrade file available from NSM 2012.1 download page is applicable to NSM 2011.x and NSM 2010.x as well. Upgrade instructions are available in NSM Installation Guide .


Workaround

There are no known workarounds that can mitigate all of the issues listed in this bulletin.

Use access lists or firewall filters to limit access to the NSM network management server only from trusted hosts.

Severity Assessment

The highest CVSSv2 Score of these vulnerabilities is 10 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

Related Information