STRM and JSA 2013 [juniper.net].2 releases prior to 2013.2R9 and JSA 2014 [juniper.net] releases prior to 2014.3R2 are affected by the following vulnerability:
STRM and JSA 2013 [juniper.net].2 releases prior to 2013.2R10 and JSA 2014 [juniper.net] releases prior to 2014.4R2 are affected by the following vulnerabilities:
Solution for CVE-2014-0118:
Solution for CVE-2014-6075, CVE-2014-4829, CVE-2014-0453, CVE-2014-4244, CVE-2014-3511, CVE-2014-5119, CVE-2014-3568, CVE-2014-3567, CVE-2014-4832, CVE-2014-4831, CVE-2014-4263 and CVE-2014-3508:
There are no known workarounds that can help mitigate all of the above issues. Limiting access to the device from only trusted hosts would help mitigate or lessen the risks of exposure to some of the issues.
2015-01-14: Initial publication. 2015-01-30: Included solution for JSA 2014 [juniper.net] releases.