Multiple vulnerabilities have been fixed in Juniper Networks NSM products (NSMXpress, NSMXpress II, NSM3000, and NSMserver) as a result of upgrading base operating system to CentOS 5.7 on NSM Appliances and RedHat EL 5.7 on software NSM installations.
Following is a list of known CVE ids that may pose a security risk to NSM products, which have been fixed as a result of this software upgrade:
These issues were discovered in a variety of ways, and all are known publicly.
Please refer to NSM release notes for a complete list of CVEs that were fixed.
These vulnerabilities are fixed in: NSM version 2012.1 and later NSM version 2011.4s4 and later NSM version 2010.3s7 and later
Note CentOS or RedHat version should also be upgraded to 5.7. CentOS 5.7 upgrade file available from NSM 2012.1 download page is applicable to NSM 2011.x and NSM 2010.x as well. Upgrade instructions are available in NSM Installation Guide .
There are no known workarounds that can mitigate all of the issues listed in this bulletin.
Use access lists or firewall filters to limit access to the NSM network management server only from trusted hosts.