CVE-2017-10606Networks Junos OS vulnerability

3 documents3 sources
Severity
4.4MEDIUMNVD
EPSS
0.1%
top 83.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 13

Description

Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX300 Series to encrypt sensitive configuration data. While other products also ship with a TPM, no other products or platforms are affected by this vulnerability. Customers can confirm the version of TPM firmware via the 'show security tpm status'

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5juniper_networks/junos_os15.1X49 prior to TPM firmware version 4.43

🔴Vulnerability Details

1
GHSA
GHSA-h472-275m-5q88: Version 42022-05-13

📋Vendor Advisories

1
Juniper
CVE-2017-10606: Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may2017-10-13