Product Affected

Junos Space and JA1500, JA2500 (Junos Space Appliance) with Junos Space 13.1 and earlier releases.
Critical
10 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

Problem

A vulnerability in Junos Space releases before 13.3R1.8 when firewall is disabled, may allow a remote unauthenticated attacker to execute arbitrary commands with root privileges leading to complete compromise of the system and devices managed by Junos Space. A firewall is enabled by default on Junos Space. This vulnerability cannot be exploited remotely when the firewall is enabled.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue has been assigned CVE-2014-3412 .

Solution

This issue is fixed in Junos Space 13.3R1.8 and all subsequent releases.

Junos Space releases can be obtained from:
http://www.juniper.net/support/downloads/?p=space#sw

Workaround

Enable firewall on Junos Space and limit access only from trusted hosts.

Severity Assessment

We consider this to be a critical issue. A remote network based attacker can get complete access to Junos Space or other devices managed by Junos Space.

Related Information

Acknowledgements