PT-2017-11403 · Juniper Networks · Srx300 Series+1
Publicado
2017-10-13
·
Atualizado
2019-10-09
·
CVE-2017-10606
CVSS v3.1
4.4
Média
| Vetor | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Juniper Networks SRX300 Series version 4.40
Description
The issue is related to a weakness in generating cryptographic keys in the TPM firmware, which could allow an attacker to decrypt sensitive information. The TPM is used for encrypting sensitive configuration data in the SRX300 Series. This problem was identified by an external security researcher.
Recommendations
For version 4.40, update the TPM firmware to a version that addresses the weakness in generating cryptographic keys.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Junos
Srx300 Series