Product Affected

These issues affect Junos Space Security Director Policy Enforcer.
Critical
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Problem

Multiple known vulnerabilities exist in CentOS 6.8, shipped with Junos Space Policy Enforcer prior to version 22.1R1.
 

Policy Enforcer is a component of the Junos Space Security Director user interface, integrated with Sky ATP to provide centralized threat management and monitoring for software-defined secure networks.
 

These issues affect all versions of Juniper Networks Junos Space Policy Enforcer prior to 22.1R1.
 

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was discovered during external security research.
 

Solution

The version of CentOS shipped with the Policy Enforcer component of Junos Space Security Director has been upgraded from CentOS 6.8 to 7.9 in version 22.1R1.
 

The following software releases have been updated to resolve this specific issue: Junos Space Security Director Policy Enforcer 22.1R1 and all subsequent releases.
 

Note: Upgrading Policy Enforcer also requires a compatible version of Junos Space Security Director.
 

This issue is being tracked as 1653068.
 

Workaround

There are no viable workarounds for this issue.
 

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-07-13: Initial publication

Related Information