The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos | Juniper | 20.2-r1 (including) | 20.2-r1 (including) |
Junos | Juniper | 20.2-r1-s1 (including) | 20.2-r1-s1 (including) |
Junos | Juniper | 20.2-r1-s2 (including) | 20.2-r1-s2 (including) |
Junos | Juniper | 20.2-r1-s3 (including) | 20.2-r1-s3 (including) |
Junos | Juniper | 20.3-r1 (including) | 20.3-r1 (including) |
Junos | Juniper | 20.3-r1-s1 (including) | 20.3-r1-s1 (including) |
Junos | Juniper | 20.4-r1 (including) | 20.4-r1 (including) |
Junos | Juniper | 20.4-r1-s1 (including) | 20.4-r1-s1 (including) |