An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which may compromise the integrity and confidentiality of the device. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D120 on SRX Series devices. No other versions of Junos OS are affected.
Solution:
Workaround:
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10952 | vendor advisory |
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-application-identification-overview.html | vendor advisory |