Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in Release R2008.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
The issues resolved in release R2008 include:
These issues have been resolved in Contrail Networking Release R2008.
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
There are no known workarounds for all these issues. It is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to Contrail from trusted, administrative networks or hosts.
2020-10-14: Initial Publication.