Multiple vulnerabilities in cURL and libcurl have been resolved in Junos OS. RISK LEVEL: CRITICAL CVSSv2 10.0, CVSSv3 9.8: Junos OS 12.3R uses cURL 7.24 and has been upgraded to cURL 7.59.0 which may be impacted by: CVE-2000-0973 , CVE-2013-1944 , CVE-2013-2174 , CVE-2013-4545 , CVE-2013-6422 , CVE-2014-0015 , CVE-2014-0138 , CVE-2014-0139 , CVE-2014-3613 , CVE-2014-3707 , CVE-2014-8150 , CVE-2015-3143 , CVE-2015-3148 , CVE-2015-3153 , CVE-2016-0754 , CVE-2016-0755 , CVE-2016-3739 , CVE-2016-4802 , CVE-2016-5419 , CVE-2016-5420 , CVE-2016-7141 , CVE-2016-7167 , CVE-2016-8615 , CVE-2016-8616 , CVE-2016-8617 , CVE-2016-8618 , CVE-2016-8619 , CVE-2016-8621 , CVE-2016-8622 , CVE-2016-8623 , CVE-2016-8624 , CVE-2016-8625 , CVE-2016-9586 , CVE-2017-1000100 , CVE-2017-1000254 , CVE-2017-1000257 , CVE-2017-7407 , CVE-2017-8817 , CVE-2018-1000007 , CVE-2018-1000120 , CVE-2018-1000121 and CVE-2018-1000122 . RISK LEVEL: CRITICAL CVSSv2 10.0, CVSSv3 9.8: Junos OS 12.1X46, 12.3X48, and Junos OS 13.1R through 17.3R release trains uses cURL 7.43 and has been upgraded to cURL 7.59.0 which may be affected by: CVE-2000-0973 , CVE-2013-1944 , CVE-2014-8150 , CVE-2016-0754 , CVE-2016-0755 , CVE-2016-3739 , CVE-2016-4802 , CVE-2016-5419 , CVE-2016-5420 , CVE-2016-5421 , CVE-2016-7141 , CVE-2016-7167 , CVE-2016-8615 , CVE-2016-8616 , CVE-2016-8617 , CVE-2016-8618 , CVE-2016-8619 , CVE-2016-8620 , CVE-2016-8621 , CVE-2016-8622 , CVE-2016-8623 , CVE-2016-8624 , CVE-2016-8625 , CVE-2016-9586 , CVE-2016-9952 , CVE-2016-9953 , CVE-2017-1000100 , CVE-2017-1000101 , CVE-2017-1000254 , CVE-2017-1000257 , CVE-2017-7407 , CVE-2017-8816 , CVE-2017-8817 , CVE-2018-1000007 , CVE-2018-1000120 , CVE-2018-1000121 and CVE-2018-1000122 . RISK LEVEL: CRITICAL CVSSv3 9.8: Subsequent releases of Junos OS 17.4R1 and onward uses cURL 7.54 and has been upgraded to cURL 7.59.0 which may be affected by: CVE-2017-1000099 , CVE-2017-1000100 , CVE-2017-1000101 , CVE-2017-1000254 , CVE-2017-1000257 , CVE-2017-8816 , CVE-2017-8817 , CVE-2017-8818 , CVE-2017-9502 , CVE-2018-1000005 , CVE-2018-1000007 , CVE-2018-1000120 , CVE-2018-1000121 , CVE-2018-1000122 Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10 on EX Series; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 12.3X54 versions prior to 12.3X54-D34 on ACX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 14.1X53 versions prior to 14.1X53-D130 on QFabric System; 15.1 versions prior to 15.1F6-S11, 15.1R4-S9, 15.1R7-S1, 15.1R8; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10000 Series; 15.1X53 versions prior to 15.1X53-D234 on QFX5110, QFX5200; 15.1X53 versions prior to 15.1X53-D471 on NFX 150, NFX 250; 15.1X54 versions prior to 15.1X54-D70 on ACX Series; 16.1 versions prior to 16.1R4-S10, 16.1R6-S4, 16.1R7; 16.2 versions prior to 16.2R1-S7, 16.2R2-S6, 16.2R3; 17.1 versions prior to 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S5, 17.2R3; 17.2X75 versions prior to 17.2X75-D100; 17.3 versions prior to 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S4, 17.4R2; 18.1 versions prior to 18.1R1-S1, 18.1R2; 18.2X75 versions prior to 18.2X75-D10. Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities. Additional details on the vulnerabilities is also available at the cURL website located at https://curl.haxx.se/docs/security.html Further details for REST API configuration, cURL, and related components can be found in the URLs section of this advisory. Important security issues resolved as a result of these upgrades include:
The following software releases have been updated to resolve this specific issue: 12.1X46-D77, 12.3R12-S10, 12.3X48-D70, 12.3X54-D34, 14.1X53-D47, 14.1X53-D130*, 15.1F6-S11*, 15.1R4-S9, 15.1R7-S1, 15.1R8, 15.1X49-D140, 15.1X53-D67, 15.1X53-D234, 15.1X53-D471, 15.1X54-D70, 16.1R4-S10, 16.1R6-S4, 16.1R7, 16.2R1-S7, 16.2R2-S6, 16.2R3, 17.1R2-S7, 17.1R3, 17.2R1-S6, 17.2R2-S5, 17.2R3, 17.2X75-D100, 17.3R2-S2, 17.3R3, 17.4R1-S4, 17.4R2, 18.1R1-S1*, 18.1R2, 18.2X75-D10, 18.2R1, and all subsequent releases. *Pending Publication
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL). This issue is being tracked as PR 1347361 which is visible on the Customer Support website.
Actions which may reduce the risk of exploitation include: Discontinue the use of cURL scripting. Avoid using untrusted URLs to fetch updates or to import data into a Junos device. Discontinue the use of HTTP with REST APIs. Utilize certificates and HTTPS with REST APIs. Consider the use of SSL/TLS mutual authentication. Limit the number of concurrent REST connections to a device to only the minimum necessary number to perform the necessary goal, thereby potentially exposing attackers or limiting the attack surface an attacker can target. Utilize non-default REST HTTPS ports to obfuscate the use of REST APIs from potential attackers. Specify the set of ciphers the server can use to perform encryption and decryption functions. Lastly, utilizing common security BCPs to limit the exploitable surface by limiting access to network and device to trusted systems, administrators, networks and hosts.
2018-07-11: Initial Publication. 2018-07-31: modified Workaround section line to read: "Discontinue the use of cURL scripting" instead of "Discontinue the use of scripts".