When xnm-ssl or xnm-clear-text is enabled within the [edit system services] hierarchy level of the Junos configuration, an unauthenticated, remote user could exploit the XNM command processor to consume excessive amounts of memory. This, in turn, could lead to system instability or other performance issues. This issue was found during internal product security testing. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue. This issue has been assigned CVE-2014-0613 .
xnm-ssl
xnm-clear-text
[edit system services]
The following software releases have been updated to resolve this specific issue:
show version detail
Use access lists or firewall filters to limit access to the router via the Junos XML protocol only from trusted hosts. In addition to the recommendations listed above, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use additional access lists or firewall filters to limit access to the router via ssh or telnet only from trusted, administrative networks or hosts.