Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in release 21.3.
These issue was discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Contrail Networking 21.3 and all subsequent releases.
These issues are being tracked as CEM-21367 and CEM-22413.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.
There are no known workarounds for these issues.
However, risk of malicious exploitation may be mitigated by limiting the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device only from trusted, administrative networks or hosts.
2022-04-13: Initial Publication.