Multiple vulnerabilities have been resolved in Juniper Networks Junos OS by upgrading OpenSSH included with Junos OS to OpenSSH 7.4, or by fixing vulnerabilities found during external security research.
These issues affect:
Juniper Networks Junos OS:
[system services ssh]
Customers can determine what version of SSH they are running by issuing the following command:
root@device> start shell command "ssh -V"
Example output would show something similar to the following, providing the versions for OpenSSL and OpenSSH in the same line:
OpenSSH_7.5, SSH protocols 1.5/2.0, OpenSSL 1.0.2u 20 Dec 2019
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
This issue was discovered during a external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Junos OS: 17.2R3-S4, 17.3R3-S8, 17.3R4, 17.4R2-S9, 17.4R3, 18.1R3-S13, 18.1R4, 18.2R2-S7, 18.2R3, 18.3R1-S7, 18.3R2, 18.4R1-S7, 18.4R2, 19.1R1-S4, 19.1R2, 19.2R1, and all subsequent releases.
These issues are being tracked as 1241002 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2021-04-14: Initial Publication.