A vulnerability in the NSM XDB service on devices with NSM versions prior to 2012.2R8 may allow a remote unauthenticated attacker to run arbitrary code with root privileges on the device. Compromise of the NSM device may allow an attacker to gain control of other devices managed by NSM. This issue was discovered by an external security researcher. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue. This issue has been assigned CVE-2014-3411 .
The following software releases have been updated to resolve this specific issue:
NSM Software releases are available from http://www.juniper.net/support/downloads/?p=nsm#sw .
Use access lists or firewall filters to limit access to the NSM device only from trusted hosts. Please refer to KB25681 [juniper.net] .
Juniper SIRT would like to acknowledge an anonymous researcher working with HP TippingPoint Zero Day Initiative (ZDI) for responsibly reporting this vulnerability.