Multiple vulnerabilities have been resolved in the Junos Space 21.2R1 release by updating third party software included with Junos Space or by fixing vulnerabilities found during external security research.
These issues affect Juniper Networks Junos Space versions prior to 21.2R1.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Junos Space 21.2R1, and all subsequent releases.
These issues are being tracked as 1584229 and 1594676 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
There are no known workarounds for these issues.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to the device to only trusted administrative networks, hosts and users.
2021-07-14: Initial Publication. 2021-08-17: CVSS Base Score downgraded from 10.0 to 9.8. CVE-2020-1472 while this vulnerability exists in the source code, it is not exploitable due to the shipping configuration not having the feature enabled. To exploit this issue an attacker must be able to modify the running configuration of the device which requires high privileges to the system. To resolve this CVE completely customers must upgrade. There is no workaround, such as removing the subsystem, upgrading the subsystem, or modifying the system configuration to protect against an attacker with high privilges on the device being able to enable this vulnerability.