Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-10606 Details

Description

Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX300 Series to encrypt sensitive configuration data. While other products also ship with a TPM, no other products or platforms are affected by this vulnerability. Customers can confirm the version of TPM firmware via the 'show security tpm status' command. This issue was discovered by an external security researcher. No other Juniper Networks products or platforms are affected by this issue.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions
juniper trusted platform module firmware
4.40

CPE

  • cpe:2.3:o:juniper:trusted_platform_module_firmware:4.40:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
juniper srx300
All versions

CPE

  • cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
juniper srx320
All versions

CPE

  • cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
juniper srx340
All versions

CPE

  • cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
juniper srx345
All versions

CPE

  • cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-10606
NVD Published Date:
Oct 13, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-10606 Details - Not Deferred