The OpenSSL project has published a set of security advisories for vulnerabilities resolved in the OpenSSL library in December 2015, March, May, June, August and September 2016. The following is a summary of these vulnerabilities and their status with respect to Juniper products:
CVE-2016-2176 is a vulnerability that only affects EBCDIC systems. No Juniper products are affected by this vulnerability.
Affected Products:
Junos OS: Junos OS is potentially affected by many of these issues. Junos OS is not affected by CVE-2016-0701, CVE-2016-0800, CVE-2016-2107, CVE-2016-2176, CVE-2016-2179, CVE-2016-2181, CVE-2016-6308, CVE-2016-6309 and CVE-2016-7052.
ScreenOS: ScreenOS is potentially affected by many of these issues. ScreenOS is not affected by CVE-2015-1794, CVE-2015-3193, CVE-2015-3194, CVE-2015-3196, CVE-2015-3197, CVE-2016-0701, CVE-2016-0702, CVE-2016-0705, CVE-2016-0798, CVE-2016-0799,CVE-2016-2107, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309 and CVE-2016-7052
Junos Space: Junos Space is potentially affected by many of these issues. Junos Space is not affected by CVE-2015-1794, CVE-2016-0705, CVE-2016-0798, CVE-2016-2176, CVE-2015-3193, CVE-2015-3196, CVE-2016-0701, CVE-2016-2107, CVE-2016-6305, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309 and CVE-2016-7052.
NSM: NSM server software and NSM Appliances (NSM4000, NSM3000, NSMXpress appliance) are potentially affected by many of these issues. NSM is not affected by CVE-2015-1794, CVE-2016-0705, CVE-2016-0798, CVE-2016-2176, CVE-2015-3193, CVE-2015-3196, CVE-2016-0701, CVE-2016-2107, CVE-2016-6305, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309 and CVE-2016-7052.
Juniper Secure Analytics (JSA, STRM): STRM, JSA series is potentially affected by these issues.
CTPView/CTPOS: CTPView and CTPOS are potentially affected by many these issues. CTPView and CTPOS are not affected by CVE-2015-1794, CVE-2016-0705, CVE-2016-0798, CVE-2016-2176, CVE-2015-3193, CVE-2015-3196, CVE-2016-0701, CVE-2016-2107, CVE-2016-6305, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309 and CVE-2016-7052.
Junos OS:
OpenSSL December 2015 advisory: CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196 and CVE-2015-1794 are resolved in 12.1X44-D60, 12.1X46-D45, 12.1X46-D51, 12.1X47-D35, 12.3R12, 12.3R13, 12.3X48-D25, 13.2X51-D40, 13.3R9, 14.1R7, 14.1X53-D35, 14.2R6, 15.1F5, 15.1R3, 15.1X49-D40, 15.1X53-D35, 16.1R1 and all subsequent releases (PR 1144520).
OpenSSL March 2016 advisory: CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0702, CVE-2016-0703 and CVE-2016-0704 are resolved in 13.3R10*, 14.1R8, 14.1X53-D40*, 14.2R7, 15.1F5-S4, 15.1F6, 15.1R4, 15.1X49-D60, 15.1X53-D50, 16.1R1 and all subsequent releases (PR 1165523, 1165570).
OpenSSL May 2016 advisory: CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2180 are resolved in 13.3R10, 14.1R9, 14.1X53-D40, 14.1X55-D35, 14.2R4-S7, 14.2R8, 15.1F5-S4, 15.1F6-S2, 15.1R4, 15.1R8, 15.1X53-D50, 15.1X53-D60, 16.1R1, and all subsequent releases (PR 1180391).
OpenSSL June to September 2016 advisories: CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183*, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-7052 are resolved in 12.1X46-D65, 13.3R10, 14.1R9, 14.1X55-D35, 14.2R8, 15.1F5-S5, 15.1R4-S5, 15.1R5, 15.1X49-D70, 16.1R3, and all subsequent releases. Fixes are in progress for other supported Junos releases (PR 1216923).
CVE-2016-2108 was resolved when fixes for OpenSSL Advisories in June and July 2015 were implemented in Junos. At that time OpenSSL version was upgraded to 1.0.1p in Junos 13.3 and later releases which included a fix for this issue. Please see JSA10694 [juniper.net] for solution releases.
*CVE-2016-2183 was addressed by OpenSSL by moving the DES ciphersuites from the HIGH cipherstring group to the MEDIUM cipherstring group. However, SSLCipherSuite in the Junos OS releases listed above still reference +MEDIUM. Junos OS 12.1X46-D66, 12.3X48-D50, 14.1R9, 14.2R8, 15.1R7, 15.1X49-D80, 16.1R5, 16.2R2, and 17.1R3 have been updated to exclude the MEDIUM cipherstring group, and all future releases of Junos OS will implement this change as well. The enhancement is being tracked as PR 1216745, and this advisory will be updated as new releases implement this change.
Note: While Junos is not affected or impacted by certain CVEs, fixes for those get included with the relevant OpenSSL version upgrade. Hence these are stated as resolved.
ScreenOS:
CVE-2015-3195 is resolved in 6.3.0r22. This issue is being tracked as PR 1144749. Please see JSA10733 [juniper.net] further details.
CVE-2016-0797, CVE-2016-0800, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108 have been resolved in ScreenOS 6.3.0r23. These issues are being tracked as PRs 1180504 and 1165796. CVE-2016-0703 and CVE-2016-0704 are resolved by disabling SSLv2 on ScreenOS devices. SSLv2 and SSLv3 are disabled by running "unset ssl ssl3" command. Fixes for issues in OpenSSL September advisory that impact ScreenOS are being tracked as PR 1217005.
Junos Space:
OpenSSL software has been upgraded to 1.0.1t in Junos Space 16.1R1 to resolve all the issues included in OpenSSL advisories until May 2016. These issues are being tracked as PRs 1144741, 1158268, 1165853, 1180505, 1212590.
OpenSSL software has been upgraded to CentOS openssl-1.0.1e-57.el6 in Junos Space 17.1R1 (future release) to resolve the issues included in OpenSSL advisories from June to September. These issues are being tracked as PR 1216998.
NSM: OpenSSL software included with NSM server software has been upgraded to 1.0.2h in NSM 2012.2R13 to resolve all the issues included in OpenSSL advisories until May 2016. This upgrade is being tracked as PR 1198397. Fixes for issues in OpenSSL advisories from June to September 2016 are being tracked as PR 1217003. OpenSSL RPM included with NSM Appliance OS based on CentOS 6 is being upgraded in the gZip v3 release of the OS image to resolve all these vulnerabilities. Note: While NSM server software does not depend on the OS provided OpenSSL RPMs, other system components may depend on it. Where NSM server software is installed on a generic Linux or Solaris server, it is recommended to apply fixes provided by the server OS vendor. Note: NSM Appliance OS based on CentOS 5 will not be updated. Customers must use the NSM Appliance OS based on CentOS 6.
Juniper Secure Analytics (JSA, STRM):
OpenSSL December 2015 and March 2016 advisories: CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794, CVE-2015-3193, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799 and CVE-2016-0800 have been resolved in 2014.6.R4. OpenSSL September 2016 advisories: CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, and CVE-2016-7052 have been resolved in 2014.8.R4.
These issues are being tracked as PRs 1151137, 1165861, and 1217006.
CTPView
CVE-2015-3194 and CVE-2015-3195 have been resolved in 7.1R3, 7.2R1 and all subsequent releases (PR 1144746).
CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0797, CVE-2016-0799 and CVE-2016-0800 have been resolved in 7.1R3, 7.2R2, 7.3R1 and all subsequent releases (PR 1165849).
CVE-2015-3194 and CVE-2015-3195 have been resolved in 7.2R1 and all subsequent releases (PR 1144964).
CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0797, CVE-2016-0799 and CVE-2016-0800 have been resolved in 7.0R7, 7.1R3, 7.2R2, 7.3R1 and all subsequent releases (PR 1165847).
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
Standard security best current practices (control plane firewall filters, edge filtering, access lists, etc.) may protect against any remote malicious attacks.
Junos OS
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include:
ScreenOS
Methods to reduce the risk associated with this issue include:
General Mitigation
It is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the HTTPS or SSL/TLS services only from trusted, administrative networks or hosts.
2016-10-12: Initial publication 2016-10-17: Updated ScreenOS problem section with additional CVEs that do not affect ScreenOS. Updated ScreenOS solution with specific resolved CVEs. 2016-10-26: Updated fixed Junos OS releases for OpenSSL September 2016 advisories. 2016-11-14: Included statement about NSM Appliance OS in the solution. 2016-11-29: Additional versions of Junos OS updated to address OpenSSL September 2016 advisories. 2016-12-16: Updated CVE IDs and versions of Junos OS resolving the OpenSSL September 2016 advisories. 2017-03-05: Category restructure. 2017-03-14: Added STRM fixes for OpenSSL September 2016 advisories. 2017-05-08: Clarified that Junos OS was updated to include the OpenSSL ciphergroup mitigation described in CVE-2016-2183, but not all releases of Junos OS currently exclude the MEDIUM ciphersstring group. All supported version of Junos OS will be updated to include an SSLCipherSuite of -MEDIUM. 2017-05-09: Junos Space upgraded to openssl-1.0.1e-57.el6 in 17.1R1 (due end of Q2/2017) to address the OpenSSL June and September 2016 advisories. 2017-05-18: More Junos OS releases added to resolve CVE-2016-2183. 2018-12-17: Updated solution releases for OpenSSL May 2016 advisory.