Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

2014-05 Security Bulletin: Junos Space: Arbitrary command execution vulnerability (CVE-2014-3412)



Article ID: JSA10626 SECURITY_ADVISORIES Last Updated: 14 May 2014Version: 1.0
Product Affected:
Junos Space and JA1500, JA2500 (Junos Space Appliance) with Junos Space 13.1 and earlier releases.

A vulnerability in Junos Space releases before 13.3R1.8 when firewall is disabled, may allow a remote unauthenticated attacker to execute arbitrary commands with root privileges leading to complete compromise of the system and devices managed by Junos Space. A firewall is enabled by default on Junos Space. This vulnerability cannot be exploited remotely when the firewall is enabled.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue has been assigned CVE-2014-3412.

This issue is fixed in Junos Space 13.3R1.8 and all subsequent releases.
Enable firewall on Junos Space and limit access only from trusted hosts.

Junos Space releases can be obtained from:

CVSS Score:
10 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Severity Level:
Severity Assessment:
We consider this to be a critical issue. A remote network based attacker can get complete access to Junos Space or other devices managed by Junos Space.

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search