NTP.org has published security advisories for vulnerabilities resolved in ntpd (NTP daemon). The following is a summary of the vulnerabilities that may impact Junos OS:
The following software releases have been updated to resolve these specific issues: Junos OS 12.1X46-D77, 12.3R12-S10, 12.3R13, 12.3X48-D70, 12.3X54-D34, 14.1X53-D47, 15.1R4-S9, 15.1R7-S1, 15.1X49-D140, 15.1X53-D234, 15.1X53-D471, 15.1X53-D490, 15.1X53-D59, 15.1X53-D67, 16.1R4-S9, 16.1R6-S4, 16.1R7, 16.2R1-S7, 16.2R2-S6, 16.2R3, 17.1R1-S7, 17.1R2-S7, 17.1R3, 17.2R1-S6, 17.2R2-S4, 17.2R3, 17.3R1-S5, 17.3R2-S2, 17.3R3, 17.4R1-S4, 17.4R2, 18.1R2, 18.2R1, 18.2X75-D5, 18.3R1, and all subsequent releases.
These issues are being tracked as PR 1343195 which is visible on the Customer Support website. Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
Standard security best current practices (control plane firewall filters, edge filtering, access lists, etc.) will protect against any remote malicious attacks against NTP. Customers who have already applied the workaround described in JSA10613 [juniper.net] are already protected against any remote exploitation of these vulnerabilities. Refer to the Workaround section of JSA10613 [juniper.net] for specific applicable IPv4 mitigation techniques. The firewall filters in the Workaround section of JSA10613 [juniper.net] can also be updated or duplicated to protect IPv6 port 123/udp using ' next-header udp ' and ' port ntp '.
next-header udp
port ntp
2018-10-10: Initial publication