Modern microprocessors that implement speculative execution of instructions are susceptible to a new class of cache timing attacks being called "Meltdown" and "Spectre". These vulnerabilities could allow an attacker to read privileged memory which may contain sensitive information such as passwords or encryption keys. There are three known variants of the issue:
% sysctl security.mac.veriexec.state
security.mac.veriexec.state: loaded active enforce
/sbin/veriexec -i enforce
% /sbin/veriexec -i enforce || echo "ERROR: veriexec not enforced" %
% /sbin/veriexec -i enforce || echo "ERROR: veriexec not enforced" ERROR: veriexec not enforced %
In order to mitigate this vulnerability, only run software from trusted sources. It is also recommended to limit the access to critical infrastructure networking equipment to only trusted administrators from trusted administrative networks or hosts.
2018-01-05: Initial publication 2018-01-08: Minor update on the Product Status section 2018-01-11: Update on the problem description with regards to information on multiple layers of protection and minor update on product status 2018-01-12: Update on the Product Status section 2018-01-18: Update on the Product Status section SRX6500->SRX650 2018-01-24: Additional information to check veriexec enforcement on older Junos OS releases: /sbin/veriexec -i enforce 2018-02-02: Update on the Product Status section LN1000 and LN2600 2018-02-20: Update on AppFormix 2018-02-22: Update on WANDL IP/MPLSView