Multiple vulnerabilities have been addressed in the Session and Resource Control (SRC) software by updating the Bouncy Castle package to version 1.62.
This issue affects Juniper Networks SRC:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during an external security research.
The important security issue resolved is described below:
The following software releases have been updated to resolve this specific issue: SRC 4.12.0-R4, 4.13.0-R2, and all subsequent releases.
This issue is being tracked as 1465792 .
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
There are no viable workarounds for this issue.
To reduce the risk of exploitation allow access to the device from only trusted networks, administrators and hosts.
2020-07-08: Initial publication