PT-2017-11403 · Juniper Networks · Srx300 Series+1

Published

2017-10-13

·

Updated

2019-10-09

·

CVE-2017-10606

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks SRX300 Series version 4.40
Description The issue is related to a weakness in generating cryptographic keys in the TPM firmware, which could allow an attacker to decrypt sensitive information. The TPM is used for encrypting sensitive configuration data in the SRX300 Series. This problem was identified by an external security researcher.
Recommendations For version 4.40, update the TPM firmware to a version that addresses the weakness in generating cryptographic keys.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-10606

Affected Products

Junos
Srx300 Series