Product Affected

These issues affect specific products and platforms. Refer to the Problem section below for more information.
High
7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Problem

Multiple buffer overrun vulnerabilities in OpenSSL 3.0 prior to OpenSSL 3.0.7 can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.
 

These issues only affect OpenSSL 3.0.0 and later releases. Earlier versions, such as OpenSSL 0.9.x, 1.0.x and 1.1.x, are unaffected by these vulnerabilities.


These issues affect:

  • Juniper Networks Junos OS Evolved versions later than 22.1R1-EVO.


These issues do not affect:

  • Juniper Networks Junos OS Evolved versions prior to 22.1R1-EVO;
  • Juniper Networks Junos OS;
  • Juniper Networks Mist;
  • Juniper Networks CTPOS;
  • Juniper Networks CTPView;
  • Juniper Networks 128T (Session Smart Router);
  • Juniper Networks SBR Carrier;
  • Juniper Networks Paragon Active Assurance (formerly Netrounds).
     

Other products and platforms are still under investigation.

Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.

These issues were reported by a third-party software provider.

Important security vulnerabilities resolved in this release include: CVE-2022-3602 and CVE-2022-3786 .

Note: The CVSS score shown above is an initial assessment by the Juniper SIRT. An official CVSS score has not been provided by the OpenSSL project at this time. Once an official CVSS score is published, this advisory will be updated accordingly.

Solution

Software will be updated to resolve these two issues by upgrading OpenSSL to 3.0.7 in all affected product, platforms, and releases.

This advisory will be updated as fixes for affected releases are made available.

Workaround

Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos OS Evolved may include:

  • Disabling J-Web
  • Disable SSL service for JUNOScript and only use Netconf, which makes use of SSH, to make configuration changes
  • Limit access to J-Web and XNM-SSL from only trusted networks


Due to the nature of this specific vulnerability, in addition to the recommendations listed above, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit management access to the device via only from trusted, administrative networks or hosts.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-11-01: Initial Publication

Related Information