Third party software upgrades provided with NSM offline or online upgrade package v3 resolve the following vulnerabilities that affect NSM 2012.2 releases on NSM Appliances NSM3000 and NSMXpress:
Note: NSM server software installed on generic Linux or Solaris servers may require OpenSSH fixes from server OS vendor.
All these issues are fixed by " NSM Appliance Generic Offline Upgrade Package_v3 - CentOS 5.x " or " NSM Appliance Generic Online Upgrade Script_v3_CentOS5.x " (released Sep 30, 2014) or later. These are available for download from https://www.juniper.net/support/downloads/?p=nsm#sw .
NSM Appliance Upgrade Package_v3 are available at http://www.juniper.net/support/downloads/?p=nsm#sw .
Use access lists or firewall filters to limit access to the NSM server only from trusted hosts.
2014-11-14: Initial publication.