The OpenSSL project has published a security advisory for vulnerabilities resolved in the OpenSSL 1.1.1 library on August 24, 2021.
These issues affect Juniper Networks Junos OS:
This issue does not affect Juniper Networks Junos OS versions prior to 21.2R1.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
The important security issue resolved is described below:
Junos OS has been upgraded to OpenSSL 1.1.1l.
The following software releases have been updated to resolve this specific issue: 21.2R2, 21.3R2, 21.4R1, and all subsequent releases.
This issue is being tracked as 1618985 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include:
2022-01-12: Initial Publication.