Back

HIGH

SRX Series: Antivirus updates are downloaded without verification

Published Oct 13, 2017

Description

Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;

Affected products

Remediation

Vendor solution

There are no viable workarounds for this issue.

It is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device from trusted, administrative networks or hosts.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Oct 13, 2017
Updated Sep 16, 2024
Reserved Jun 28, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a