Multiple vulnerabilities in OpenSSL have been resolved in the Juniper Networks Steel-Belted Radius (SBR) Carrier AAA (Authentication, Authorization, and Accounting) server.
These issues affect Juniper Networks SBR Carrier:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during an external security research.
OpenSSL in SBR Carrier has been upgraded to OpenSSL 1.0.2q which resolved the following vulnerabilities in OpenSSL:
The following software releases have been updated to resolve these specific issues: SBR Carrier 8.4.1R13, 8.5.0R4, and all subsequent releases.
These issues are being tracked as 1414678 .
Software release Service Packages are available at http://support.juniper.net from the "Download Software" links.
2020-01-08: Initial Publication