News Juniper Networks code review reveals no new backdoors

Technoglitch

Core Member
After Juniper Networks discovered unauthorized code in its networking gear late last year, the company's developers launched an internal code review for its other networking product lines. As a result of the effort, Juniper found and patched a number of security vulnerabilities in Junos OS, the FreeBSD-based operating system used in Juniper's routing, switching, and security devices, that could lead to privilege escalation, denial-of-service, and spoofing attacks.


The good news is Juniper didn't uncover any vulnerabilities that were already being exploited. More good news: The patches are available and should be applied.

Issues fixed in Junos OS
Juniper's internal product security testing team found multiple escalation-of-privilege flaws in Junos OS. Attackers can exploit certain combinations of Junos OS command-line commands and arguments to gain root access (CVE-2016-1271) to the operating system, according to the Juniper Networks SIRT (Security Incident Response Team). The vulnerability, which has a common vulnerability scoring system (CVSS) value of 7.8 and is rated as high severity, would let attackers achieve elevated privileges and gain complete control of the device, the advisory warned. Fixes are available in the following versions: Junos OS 12.1X46-D45, 12.1X47-D30, 12.3R11, 12.3X48-D25, 13.2R8, 13.3R7, 14.1R6, 14.2R4, 15.1R1, 15.1F2, 15.1X49-D15, and all subsequent releases.

"No other Juniper Networks products or platforms are affected by these issues," the advisory said.

Juniper Networks code review reveals no new backdoors | InfoWorld
 
Top