Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in release 2011.
Additionally, CVE-2015-4335 CVE-2018-11218 affect Contrail Networking 3.2.16, 3.2.17 and are resolved in 3.2.18.
These issues affect Juniper Networks Contrail Networking versions prior to 2011 and 3.2.18.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Contrail Networking 2011, 3.2.18 and all subsequent releases.
These issues are being tracked as CEM-19317, CEM-18634, CEM-18630, CEM-18633, CEM-18631 and CEM-21078.
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
There are no known workarounds for these issues.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to Contrail Networking to only trusted administrative networks, hosts and users.
2021-07-14: Initial Publication.