Vulnerabilities in OpenSSH, Apache HTTP server, Libxml2, Linux Kernel, PostgreSQL and other third party software potentially affect NSM Appliance OS.
These software packages are updated in the NSM Appliance OS gzip upgrade package v3 based on CentOS 6. Important security issues resolved as a result of this upgrade include,
Please refer to JSA10759 [juniper.net] for a list of OpenSSL vulnerabilities resolved. Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities on NSM Appliances.
All these issues are resolved in NSM Appliance Upgrade Package v3 based on CentOS 6 (released January 11, 2017).
OpenSSH upgrade issue is being tracked as PR 1181267 and is visible on the Customer Support website.
NSM Maintenance Releases are available at http://www.juniper.net/support/downloads/?p=nsm#sw .
2017-01-11: Initial release. 2017-01-17: Solution is now available for download; Updated the list of important third party software upgraded, and related CVEs.
Use access lists or firewall filters to limit access to the NSM Appliance only from trusted hosts.