The OpenSSL project has published a security advisory for a vulnerability resolved in the OpenSSL library on December 20, 2019.
This issue affects:
Juniper Networks Junos OS:
Juniper Networks Junos OS Evolved:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during an external security research.
The important security issue resolved is described below:
The following software releases have been updated to resolve this specific issue:
Junos OS: 15.1R7-S7, 15.1X49-D230, 15.1X53-D593, 16.1R7-S8, 17.2R3-S4, 17.3R3-S8, 17.4R2-S10, 17.4R3-S1, 18.1R3-S10, 18.2R2-S7, 18.2R3-S4, 18.2X75-D60, 18.3R1-S7, 18.3R2-S4, 18.3R3-S2, 18.4R2-S4, 18.4R3-S1, 19.1R1-S5, 19.1R2-S1, 19.1R3, 19.2R1-S4, 19.2R2, 19.3R2-S2, 19.3R3, 19.4R1-S1, 19.4R2, 20.1R1, and all subsequent releases.
Junos OS Evolved: 19.1R3-EVO,19.2R2-EVO, 19.3R3-EVO, 19.4R2-EVO, 20.1R1-EVO, and all subsequent releases.
This issue is being tracked as 1479780 and 1485711 .
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include:
In addition to the recommendations listed above, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the router via SSL only from trusted, administrative networks or hosts.
2020-07-08: Initial Publication