PT-2017-2538 · Microsoft+2 · Active Directory+3

Published

2017-07-12

·

Updated

2019-10-09

·

CVE-2017-2343

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions 12.3X48-D30 through 12.3X48-D35 Junos OS versions 15.1X49-D40 through 15.1X49-D50
Description The Integrated User Firewall (UserFW) feature in Junos OS has a security issue due to hardcoded credentials. This can be exploited by an attacker to compromise SRX Series devices and potentially LDAP and Active Directory integrated points, allowing access to user credentials, workstations, and servers. The attacker may gain full administrative control over one or more Active Directories, depending on the credentials supplied by the administrator.
Recommendations For Junos OS versions 12.3X48-D30 through 12.3X48-D35, update to version 12.3X48-D35 or later. For Junos OS versions 15.1X49-D40 through 15.1X49-D50, update to version 15.1X49-D50 or later. As a temporary workaround, consider disabling the UserFW service until a patch is available. Restrict access to the Active Directory authentication module to minimize the risk of exploitation. Avoid using the active-directory-access service in the affected API endpoint until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01749
CVE-2017-2343

Affected Products

Active Directory
Junos
Ldap
Srx Series