The OpenSSL project has published a security advisory for vulnerabilities resolved in the OpenSSL library on December 7, 2017. The following is a summary of these vulnerabilities and their status with respect to Juniper products:
Junos:
The following software releases have been updated to resolve this specific issue: 12.3X48-D70, 14.1R9, 14.1X53-D130, 14.1X53-D47, 15.1R6-S6, 15.1R7, 15.1X49-D130, 15.1X53-D233, 15.1X53-D471, 15.1X53-D59, 15.1X53-D67, 16.1R3-S8, 16.1R5-S4, 16.1R6-S3, 16.2R1-S6, 16.2R2-S5, 17.1R2-S6, 17.2R2-S3, 17.3R3*, 17.4R2*, 18.1R1, and all subsequent releases.
*Late availability
NorthStar:
The following software releases have been updated to resolve this specific issue: NorthStar 3.0.2, 3.1.1, 3.2.1, and all subsequent releases.
NSM:
The following software releases have been updated to resolve this specific issue: 2012.2R14, and all subsequent releases.
CTPView:
The following software releases have been updated to resolve this specific issue: 7.3R4, 7.4R2, and all subsequent releases.
CTPOS:
The following software releases have been updated to resolve this specific issue: 7.3R4, 7.4R1, and all subsequent releases.
This advisory will be updated as additional products are analyzed and fixes become available.
These issues are being tracked as PR 1328891, 1328901, 1328898, 1328896, 1328895 and 1250405 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
Junos : Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include:
Others : Limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device via SSL only from trusted, administrative networks or hosts.
2018-04-11: Initial Publication