[edit system ntp]
The following software releases have been updated to resolve these specific issues: Junos OS 12.1X46-D66, 12.3X48-D45, 14.1R8-S3, 14.1R9, 14.1X53-D44, 14.2R4-S8, 14.2R7-S6, 14.2R8, 15.1F2-S16, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6, 15.1X49-D80, 15.1X53-D231, 15.1X53-D64, 15.1X53-D70, 16.1R3-S3, 16.1R4-S1, 16.1R5, 16.2R1-S3, 16.2R2, 17.1R1, 17.2R1, and all subsequent releases.These issues are being tracked as PRs 1102394 1159544 1183180 1189546 1234119, and are visible on the Customer Support website.KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Standard security best current practices (control plane firewall filters, edge filtering, access lists, etc.) will protect against any remote malicious attacks against NTP. Customers who have already applied the workaround described in JSA10613 [juniper.net] are already protected against any remote exploitation of these vulnerabilities. Refer to the Workaround section of JSA10613 [juniper.net] for specific applicable IPv4 mitigation techniques.The firewall filters in the Workaround section of JSA10613 [juniper.net] can also be updated or duplicated to protect IPv6 port 123/udp using ' next-header udp ' and ' port ntp '.
next-header udp
port ntp
2017-04-12: Initial publication 2017-04-25: Additional fixed releases 2017-05-09: Explicitly stated that both IPv4 and IPv6 are affected 2017-05-18: Additional fixed releases 2023-05-02: Additional CVEs added. Where possible CVSS's updated from CVSSv2 or CVSSv3.0 to CVSSv3.1. CVSS Base Score updated to CVSSv3.1 to 7.7 from CVSSv3.0 6.5. Severity updated to High. Additional Tracking PRs added, now covering PRs 1102394 1159544 1183180 1189546 1234119 vs PRs 1159544 and 1234119 alone. 2023-05-03: CVE-2020-13817 CVE-2020-11868 added to CVE list.