Back

MEDIUM

Incorrect messages from Juniper Identity Management Service (JIMS) can trigger Denial of Service or firewall bypass conditions for SRX series devices

Published Apr 10, 2019

Description

Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows system to bypass SRX firewall policies, or trigger a Denial of Service (DoS) condition for the network.

Affected products

Remediation

Vendor solution

The following software releases have been updated to resolve this specific issue: 1.1.4 and all subsequent releases.

If suspicious or unusual usernames or IP addresses entries are present in the SRX auth table, they need to be removed from the SRX auth table.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Apr 10, 2019
Updated Sep 16, 2024
Reserved Oct 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a