Multiple vulnerabilities in OpenSSL have been resolved in the Juniper Networks Steel-Belted Radius (SBR) Carrier AAA (Authentication, Authorization, and Accounting) server.
These issues affect Juniper Networks SBR Carrier 8.6.0 versions prior to 8.6.0R15.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
OpenSSL in SBR Carrier has been upgraded to OpenSSL 1.1.1k which resolved the following vulnerabilities in OpenSSL:
The following software releases have been updated to OpenSSL 1.1.1k to resolve these specific issues: SBR Carrier 8.6.0R15, and all subsequent releases.
These issues are being tracked as 1611667 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2022-01-12: Initial Publication.