Product Affected

This issue affects all versions of Juniper Secure Analytics.
Medium
6.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

Problem

Juniper Networks JSA Series devices may be vulnerable to a TSX Asynchronous Abort condition on some Intel CPUs utilizing speculative execution. Exploitation of this vulnerability may allow an authenticated user to potentially enable information disclosure via a side channel with local access, allowing a local authenticated attacker to obtain sensitive information.

This issue was originally reported by Intel via INTEL-SA-00270 .

This issue affects all Juniper Secure Analytics versions prior to 7.4.0.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue has been assigned  CVE-2019-11135 .

 

Solution

The following software releases have been updated to resolve this specific issue: Juniper Secure Analytics 7.4.0 and all subsequent releases.

This issue is being tracked as  1504859 .
 

Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
 

Workaround

Use access lists or firewall filters to limit access to the device only from trusted hosts.

Limit access to only trusted system administrators.
 

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2020-10-14: Initial Publication

Related Information