Multiple NTP vulnerabilities have been resolved in Juniper Networks Junos OS Evolved by updating third party software where vulnerabilities were found during external security research.
These issues affect:
Juniper Networks Junos OS Evolved
Juniper Networks Junos OS is not affected by any of these issues.
NTP must be operating on the device to be affected by these issues, for example, the following minimal configuration is necessary:
[set system ntp]
Juniper SIRT is not aware of any malicious exploitation of any of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues:
Junos OS Evolved 21.2R3-S5-EVO, 21.3R3-S4-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.1R1-EVO, and all subsequent releases.
These issues are being tracked as 1685902
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-07-12: Initial Publication