An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which may compromise the integrity and confidentiality of the device. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D120 on SRX Series devices. No other versions of Junos OS are affected.
The following software releases have been updated to resolve this specific issue: 15.1X49-D120, and all subsequent releases.
Set the following command in the device for affected releases: set services application-identification download secure-download
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | >=15.1X49<15.1X49-D120 | 15.1X49-D120 | advisory ↗ |