Product Affected

NetScreen IDP stand alone platforms running IDP OS 5.1 prior to 5.1r4.
High
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Problem

IDP release 5.1r4 addresses vulnerabilities in prior releases with updated third party software. The following is a summary of vulnerabilities ordered by risk score:

CVE CVSS v2 base score Summary
CVE-2014-6271 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) Remote command injection vulnerability in Bash also known as Shellshock. See JSA10648 [juniper.net].
CVE-2010-4478 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) OpenSSH authentication bypass vulnerability related to J-PAKE.
CVE-2012-2131 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) OpenSSL Multiple buffer overflow vulnerabilities.
CVE-2012-5195 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) Perl denial of service vulnerability.
CVE-2009-3563 6.4 (AV:N/AC:L/Au:N/C:N/I:P/A:P) NTP Denial of service vulnerability.
CVE-2011-0539 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) OpenSSH ssh-keygen insecure certificate generation vulnerability.
CVE-2012-0814 3.5 (AV:N/AC:M/Au:S/C:P/I:N/A:N) OpenSSH information leak vulnerability.

Solution

All these issues are resolved in IDP 5.1r4 (released 25 Feb 2015) or later releases.

IDP Software Releases and Patches are available at https://www.juniper.net/support/downloads/ from the "Download Software" links.

Workaround

Limiting access to the device from only trusted hosts would help mitigate or reduce the risks of exposure to these issues.

Severity Assessment

Since ShellShock vulnerabilities were alerted in JSA10648 [juniper.net], CVE-2014-4478 with CVSS score of 5.8 is used to determine the risk level associated with this advisory.

Modification History

Modification History:

2015-04-08: Initial release.

Related Information

Acknowledgements