Multiple vulnerabilities have been resolved in Juniper Networks Junos OS by updating third party software included with Junos OS devices.
In Junos OS, the majority of attack vectors in this announcement require multiple chaining attack events to be successful against services which do not directly call SQLite. For the attacker to be able to access and successfully execute commands on the device, only one attack vector is known to exist.
These issues potentially allow an attacker to execute code or commands thereby allowing full access to the device.
These issues affects Juniper Networks Junos OS:
These issues are not applicable to releases prior to 15.1X49.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
Juniper SIRT is aware of publicly available SQLite exploits.
Important security issues resolved include:
The following software releases have been updated to resolve this specific issue: 15.1X49-D220, 17.2R3-S4, 17.3R3-S8, 17.4R2-S11, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S5, 18.3R2-S4, 18.3R3-S2, 18.4R1-S7, 18.4R2-S5, 18.4R3-S3, 19.1R1-S5, 19.1R2-S2, 19.1R3-S2, 19.2R1-S5, 19.2R2, 19.3R2-S3, 19.3R3, 19.4R1-S3, 19.4R2-S1, 19.4R3, 20.1R1-S2, 20.1R2, 20.2R1, and all subsequent releases.
This issue is being tracked as 1480208 .
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
To reduce the risk of exploitation:
* Discontinue the use of SLAX scripts and the REST API.
* Monitor /var/chroot/rest-api/var/log for malicious activity.
* Allow access to the device from only trusted networks, administrators and hosts and utilize jumpboxes.
2020-10-14: Initial Publication.