CTPOS releases 7.1R2 and 7.2R1 address multiple vulnerabilities in prior releases with updated third party software components. The resolved issues include:
These vulnerabilities are resolved in CTPOS 7.1R2, 7.2R1, and all subsequent releases. These issues are being tracked as PRs 1136821, 1135997, and 1135991, which are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Use access lists or firewalls to limit access to the device only from trusted hosts.
2016-04-13: Initial publication 2017-03-05: Category restructure 2020-11-20: Updated terminology