Product Affected

These issues affect any versions of Junos OS Evolved prior to 21.2R3-S5-EVO, 21.3, 21.4, 22.1, 22.2, 22.3, 22.4.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

Multiple NTP vulnerabilities have been resolved in Juniper Networks Junos OS Evolved by updating third party software where vulnerabilities were found during external security research.

These issues affect:

Juniper Networks Junos OS Evolved

  • Any versions prior to 21.2R3-S5-EVO;
  • 21.3 versions prior to 21.3R3-S4-EVO;
  • 21.4 versions prior to 21.4R3-S4-EVO;
  • 22.1 versions prior to 22.1R3-S3-EVO;
  • 22.2 versions prior to 22.2R3-EVO;
  • 22.3 versions prior to 22.3R2-EVO;
  • 22.4 versions prior to 22.4R2-EVO;

Juniper Networks Junos OS is not affected by any of these issues.

NTP must be operating on the device to be affected by these issues, for example, the following minimal configuration is necessary:

[set system ntp]

Juniper SIRT is not aware of any malicious exploitation of any of these vulnerabilities.

These issues were discovered during external security research.

Important security issues resolved include:

CVECVSSSummary
CVE-2020-138177.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H)ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.
CVE-2020-118687.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

Solution

The following software releases have been updated to resolve these specific issues:

Junos OS Evolved 21.2R3-S5-EVO, 21.3R3-S4-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.1R1-EVO, and all subsequent releases.

These issues are being tracked as 1685902

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for these issues.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2023-07-12: Initial Publication

Related Information