CTPView and CTPOS release 7.3R6 addresses multiple vulnerabilities in the OpenSSH libraries found in prior releases with updated open source software components.
This issue affects:
No other versions of CTPView and CTPOS are affected by these vulnerabilities.
This issue was discovered during an external security research.
The resolved issues include:
These vulnerabilities are resolved in CTPView and CTPOS 7.3R6 and all subsequent releases.
This issue is being tracked as PR 1438378 and 1455669 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
Use access lists or firewalls to limit access to the device only from trusted hosts.
2019-10-09: Initial Publication.