HomeSecurityJuniper Networks: patches critical vulnerabilities in firewalls

Juniper Networks: patches critical vulnerabilities in firewalls

Last week, Juniper Networks released an announcement informing its customers that it had patched certain vulnerabilities in its products that could lead to DoS.  

Juniper

The company has published more than a dozen warnings describing vulnerabilities found in systems , as well as dozens of flaws affecting third-party assets.

For the most part, the flaws affect Junos OS. However, there are also some that affect Juniper Secure Analytics, Junos Space , and Junos Space Security Director.

One of the most serious flaws identified in Juniper software is CVE-2020-1647, a critical double free affecting SRX series firewalls with ICAP redirection enabled. It could allow a remote attacker to launch a attack or execute arbitrary code by sending specially crafted HTTP messages.

However, CVE-2020-1654 is considered equally critical, as it can also lead to DoS attacks or remote code execution.

About six of the vulnerabilities are rated as high severity and can be used to carry out DoS and persistent attacks. The moderate severity flaws can also be exploited for DoS attacks.

juniper

Juniper Networks said that none of the vulnerabilities have been exploited by malicious actors to carry out attacks.

The company has also addressed dozens of vulnerabilities affecting third-party components, including issues that were fixed years ago by developers . The list includes OpenSSL, Intel firmware, Bouncy Castle, Java SE, Apache software, and more.

Last month, more than a dozen U.S. sent a letter to Juniper asking about the results of an investigation it conducted in 2015 after a backdoor in its products. The company has a month to respond to eight questions, and the deadline to provide its answers is Friday.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS