Product Affected

These issues affect Junos OS All versions prior to 20.4R3-S8, 21.1, 21.2, 21.3, 21.4, 22.1, 22.2, 22.3, 22.4, 23.2. These issues affect Junos OS Evolved All versions prior to 20.4R3-S8-EVO, 21.1-EVO, 21.2-EVO, 21.3-EVO, 21.4-EVO, 22.1-EVO, 22.2-EVO, 22.3-EVO, 22.4-EVO.
Medium
5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Problem

Multiple NTP vulnerabilities have been resolved in Juniper Networks Junos OS and Junos OS Evolved by updating third party software where vulnerabilities were found during external security research. Please note that there is no ability within the CLI to perform any exploitation for these issues. Only shell allows sending ntpq queries to remote systems.

These issues affect:
Juniper Networks Junos OS
  • All versions prior to 20.4R3-S8;
  • 21.1 version 21.1R1 and later versions prior to 21.2R3-S6;
  • 21.3 versions prior to 21.3R3-S5;
  • 21.4 versions prior to 21.4R3-S4;
  • 22.1 versions prior to 22.1R3-S3;
  • 22.2 versions prior to 22.2R3-S1;
  • 22.3 versions prior to 22.3R2-S2, 22.3R3;
  • 22.4 versions prior to 22.4R2-S1, 22.4R3;
  • 23.2 versions prior to 23.2R2.
Juniper Networks Junos OS Evolved
  • All versions prior to 20.4R3-S8-EVO;
  • 21.1-EVO version 21.1R1-EVO and later versions prior to 21.2R3-S6-EVO;
  • 21.3-EVO versions prior to 21.3R3-S5-EVO;
  • 21.4-EVO versions prior to 21.4R3-S4-EVO;
  • 22.1-EVO versions prior to 22.1R3-S3-EVO;
  • 22.2-EVO versions prior to 22.2R3-S2-EVO;
  • 22.3-EVO versions prior to 22.3R2-S2-EVO, 22.3R3-S1-EVO;
  • 22.4-EVO versions prior to 22.4R2-S1-EVO, 22.4R3-EVO.

As these issues are invoked via the ntpq utility from the shell there is no minimal configuration necessary to be configured on a system.


Juniper SIRT is not aware of any malicious exploitation of any of these vulnerabilities.


These issues were discovered during external security research.

Important security issues resolved include:

CVECVSSSummary
CVE-2023-265515.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
CVE-2023-265525.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
CVE-2023-265535.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
CVE-2023-265545.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
CVE-2023-265550.0 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N )praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GPS receiver. NOTE: This issue does not affect any Juniper Networks products.
 

Solution

The following software releases have been updated to resolve these specific issues:


Junos OS: 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.2R1, and all subsequent releases.


Junos OS Evolved: 20.4R3-S8-EVO, 21.2R3-S6-EVO, 21.3R3-S5-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-S2-EVO, 22.3R2-S2-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases.


Note: CVE-2023-26555 does not affect any Juniper products.


These issues are being tracked as PR 1729126 which is visible on the Customer Support website.


Note: Juniper SIRT's policy [juniper.net] is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for these issues.


We suggest that the use of any locally authenticated shell-based ntpq queries be discontinued from further use.


If it is necessary for organizations to invoke the nptq command from the shell to query remote devices, organizations can avoid these issues by using ‘-c raw’ options in ntpq invocation from the shell for that specific session when running the command.

“ntpq -c raw <other options>”


Where the “<other options>” includes the IP address of the remote device where the query needs to be sent.


This does not work around these issues and doesn't remediate the risk that an authenticated session with shell access can invoke the ntpq command without these options.


To reduce the risk of exploitation of these issues, restrict users who can access the device shell, and disallow further use of the ntpq command without -c raw as part of operational procedures. Additionally, monitor, alert, and audit for the use of ntpq in the shell as part of operational procedures ongoing.


Further, to reduce the risk of DDoS amplification attacks in general, per ntp.org: "NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to being used in distributed denial-of-service (DDoS) attacks. Please also take this opportunity to defeat denial-of-service attacks by implementing Ingress and Egress filtering through BCP38." Please see the URLs section for further details.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2023-10-11: Initial Publication

Related Information