During a software upgrade of an SRX Series services gateway to Junos OS 12.1X44 or 12.1X45 using the 'no-validate' option, a configuration validation error during the config commit phase of the boot-up sequence may leave the device with a partial configuration, allowing for unauthenticated access. An example of such an error during boot is shown below:
Loading configuration ... [edit security forwarding-process application-services] 'maximize-idp-sessions' inline-tap must be specified mgd: error: commit failed: (statements constraint check failed) Warning: Commit failed, activating partial configuration. Warning: Edit the router configuration to fix these errors.
The following software releases have been updated to resolve this specific issue:
Resolve any configuration check failures, and then reboot the SRX services gateway. Avoid using the 'no-validate' option of the 'request system software' command. In addition to the recommendations listed above, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device only from trusted, administrative networks or hosts.