The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All versions prior to 20.2R3; 20.3 versions prior to 20.3R2; 20.4 versions prior to 20.4R2.
Solution:
Workaround:
The product uses a hard-coded, unchangeable cryptographic key.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://kb.juniper.net/JSA11157 | vendor advisory |