Domestic releases of the JUNOS software include the OpenSSL software for managing authentication certificates and for managing the router through the JUNOScript application. Due to a coding error, when processing an SSL/TLS ChangeCipherSpec message, OpenSSL may fail to check that a new cipher was previously negotiated. As a result of this failure, the JUNOScript application might stop operating. This vulnerability is described in more detail in the OpenSSL Security Advisory and the associated FreeBSD Security Advisory . Note: The OpenSSL advisory refers to an additional vulnerability when using Kerberos ciphersuites. Since neither JUNOS nor SDX software is capable of using Kerberos ciphersuites, the additional vulnerability is not applicable.
The JUNOS software has been modified to properly detect that a new cipher had been previously negotiated. If a new cipher was not previously negotiated, the request to change to the new cipher is rejected.
For JUNOS software, the corrected software is available in all JUNOS software releases built on or after March 18, 2004. Contact Juniper Networks Technical Assistance Center for software availability and download instructions. As a workaround, customers can disable the JUNOScript SSL server using the command
[edit] user@router# deactivate system service xnm-ssl