The OpenSSL project has published a security advisory for vulnerabilities resolved in the OpenSSL library on January 26, 2017. The following is a summary of these vulnerabilities and their status with respect to Juniper products:
Junos OS, CTPView, CTPOS, and NSM are potentially affected by one or more of these issues.
Juniper Secure Analytics (JSA, STRM) and ScreenOS are confirmed to not be vulnerable to any of these issues.
This advisory will be updated as additional products are analyzed and fixes become available.
Standard security best current practices (control plane firewall filters, edge filtering, access lists, etc.) may protect against any remote malicious attacks.
2017-07-12: Initial publication 2017-11-20: Added NSM fixed releases