The OpenSSL project has published a set of security advisories for vulnerabilities resolved in the OpenSSL library in June and July 2015:
*CVSS v2 scores provided for backward compatibility with NVD. Junos OS is affected by one or more of these vulnerabilities. Note that CVE-2014-8176 was also included in an OpenSSL advisory, but no Juniper products use DTLS for communication.
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X44-D55, 12.1X46-D40, 12.1X47-D25, 12.3R11, 12.3X48-D20, 13.2X51-D40, 13.3R7, 14.1R6, 14.2R4, 15.1R2, 15.1X49-D20, and all subsequent releases. OpenSSL library has been upgraded to 0.9.8zg in Junos OS 12.1X44-D55, 12.1X46-D40, 12.1X47-D25, 12.3R11, 12.3X48-D20, 13.2X51-D40 and subsequent releases. OpenSSL library has been upgraded to 1.0.1p in Junos OS 12.1X46-D55, 12.1X47-D45, 12.3X48-D30, 13.3R7, 14.1R6, 14.2R4, 15.1R2, 15.1X49-D20, and all subsequent releases to resolve all vulnerabilities listed above. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. This issue is being tracked for Junos OS as PRs 1095598, 1095604, 1103020 and 1153463 which are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include:
2015-10-14: Initial publication 2016-10-05: Update the list of Junos releases which have OpenSSL 1.0.1p or later (i.e added 12.1X46-D55, 12.1X47-D45, 12.3X48-D30).