Juniper Networks JSA Series devices may be vulnerable to a TSX Asynchronous Abort condition on some Intel CPUs utilizing speculative execution. Exploitation of this vulnerability may allow an authenticated user to potentially enable information disclosure via a side channel with local access, allowing a local authenticated attacker to obtain sensitive information.
This issue was originally reported by Intel via INTEL-SA-00270 .
This issue affects all Juniper Secure Analytics versions prior to 7.4.0.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue has been assigned CVE-2019-11135 .
The following software releases have been updated to resolve this specific issue: Juniper Secure Analytics 7.4.0 and all subsequent releases.
This issue is being tracked as 1504859 .
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
Use access lists or firewall filters to limit access to the device only from trusted hosts.
Limit access to only trusted system administrators.
2020-10-14: Initial Publication