PT-2017-11403 · Juniper Networks · Srx300 Series+1
Published
2017-10-13
·
Updated
2019-10-09
·
CVE-2017-10606
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Juniper Networks SRX300 Series version 4.40
Description
The issue is related to a weakness in generating cryptographic keys in the TPM firmware, which could allow an attacker to decrypt sensitive information. The TPM is used for encrypting sensitive configuration data in the SRX300 Series. This problem was identified by an external security researcher.
Recommendations
For version 4.40, update the TPM firmware to a version that addresses the weakness in generating cryptographic keys.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos
Srx300 Series