Multiple vulnerabilities in CentOS OS implementation of CTPView OS were discovered.
JSA10691 [juniper.net] addressed some of these CVE's in CTPView OS version 7.1R1 and ongoing versions. Issues identifed include:
The following software releases have been updated to resolve this specific issue: CTPView 7.1R2, 7.2R1 and all subsequent releases. The CTPView OS Update Set was upgraded to version 5.11. This issue is being tracked as PR 1087204 and is visible on the Customer Support website. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Apply and maintain good security best current practices (BCPs) to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to networking equipment only from trusted, administrative networks or hosts.
2015-10-14: Initial publication 2015-10-30: Added BCP's to workaround section. 2016-09-20: Added CVE-2014-8159 and CVE-2014-8867. 2017-03-05: Category restructure. 2020-11-20: Updated terminology