← Back

CVE-2019-0054

nvd nist
Published: Oct 9, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which may compromise the integrity and confidentiality of the device. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D120 on SRX Series devices. No other versions of Junos OS are affected.

Affected (17)

Products: Juniper: Junos
1 product
Junos
Configuration A
17 vulnerable · 24 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 15.1x49
Version 15.1x49 d100
Version 15.1x49 d10
Version 15.1x49 d110
Version 15.1x49 d20
Version 15.1x49 d30
Version 15.1x49 d35
Version 15.1x49 d40
Version 15.1x49 d45
Version 15.1x49 d50
Version 15.1x49 d55
Version 15.1x49 d60
Version 15.1x49 d65
Version 15.1x49 d70
Version 15.1x49 d75
Version 15.1x49 d80
Version 15.1x49 d90
Running on/withPlatform Versions
Juniper
Csrx
All versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx1500
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx240
All versions
Juniper
Srx300
All versions
Juniper
Srx320
All versions
Juniper
Srx340
All versions
Juniper
Srx3400
All versions
Juniper
Srx345
All versions
Juniper
Srx3600
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx4600
All versions
Juniper
Srx5400
All versions
Juniper
Srx550
All versions
Juniper
Srx550 Hm
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions
Juniper
Vsrx
All versions

References (4)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.