Multiple vulnerabilities in Net-SNMP have been resolved in the Juniper Networks Steel-Belted Radius (SBR) Carrier AAA (Authentication, Authorization, and Accounting) server.
These issues affect Juniper Networks SBR Carrier versions prior to 8.4.1R19.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during an external security research.
Net-SNMP in SBR Carrier has been upgraded to Net-SNMP 5.8 which resolved the following vulnerabilities in Net-SNMP:
The following software releases have been updated to resolve these specific issues: SBR Carrier 8.4.1R19, 8.5.0R1, and all subsequent releases.
These issues are being tracked as 1386896 .
Software release Service Packages are available at http://support.juniper.net from the "Download Software" links.
2020-01-08: Initial Publication