Product Affected

This issue affects all versions of Junos OS and Junos OS Evolved.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

Multiple vulnerabilities have been resolved in Message Queuing Telemetry Transport (MQTT) included with Junos by fixing vulnerabilities found during external security research.
 

This issue affects:

Juniper Networks Junos OS

  • All versions prior to 19.1R3-S10;
  • 19.2 versions prior to 19.2R3-S7;
  • 19.3 versions prior to 19.3R3-S8;
  • 19.4 versions prior to 19.4R3-S11;
  • 20.1 version 20.1R1 and later versions;
  • 20.2 versions prior to 20.2R3-S7;
  • 20.3 versions prior to 20.3R3-S6;
  • 20.4 versions prior to 20.4R3-S7;
  • 21.1 versions prior to 21.1R3-S4;
  • 21.2 versions prior to 21.2R3-S5;
  • 21.3 versions prior to 21.3R3-S4;
  • 21.4 versions prior to 21.4R3-S4;
  • 22.1 versions prior to 22.1R3;
  • 22.2 versions prior to 22.2R3;
  • 22.3 versions prior to 22.3R2.

Juniper Networks Junos OS Evolved

  • All versions prior to 20.4R3-S7-EVO;
  • 21.1 version 21.1R1-EVO and later versions;
  • 21.2 version 21.2R1-EVO and later versions;
  • 21.3 version 21.3R1-EVO and later versions;
  • 21.4 versions prior to 21.4R3-S4-EVO;
  • 22.1 versions prior to 22.1R3-EVO;
  • 22.2 versions prior to 22.2R3-EVO;
  • 22.3 versions prior to 22.3R2-EVO.


To be exposed to these vulnerabilities the following configuration needs to be present:

[ system services extension-service notification ]


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


These issues were discovered during external security research.


Important security vulnerabilities resolved in this release include:

CVECVSSSummary
CVE-2017-76535.3 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients.
CVE-2017-76547.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.
CVE-2017-76557.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.

Solution

The following software releases have been updated to resolve this specific issue:

Junos OS Evolved: 20.4R3-S7-EVO, 21.4R3-S4-EVO, 22.1R3-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R1-EVO, and all subsequent releases;

Junos OS: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S11, 20.2R3-S7, 20.3R3-S6, 20.4R3-S7, 21.1R3-S4, 21.2R3-S5, 21.3R3-S4, 21.4R3-S4, 22.1R3, 22.2R3, 22.3R2, 22.4R1, and all subsequent releases.


This issue is being tracked as 1651519


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for these issues.

As a Best Common Practice (BCP) use access lists or firewall filters to limit access to the device to only trusted hosts, networks and administrators.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2023-07-12: Initial Publication

Related Information