Juniper SIRT is not aware of any malicious exploitation of any of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues:
Junos OS: 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.2R1, and all subsequent releases.
Junos OS Evolved: 20.4R3-S8-EVO, 21.2R3-S6-EVO, 21.3R3-S5-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-S2-EVO, 22.3R2-S2-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases.
Note: CVE-2023-26555 does not affect any Juniper products.
These issues are being tracked as PR 1729126 which is visible on the Customer Support website.
Note: Juniper SIRT's policy [juniper.net] is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
We suggest that the use of any locally authenticated shell-based ntpq queries be discontinued from further use.
If it is necessary for organizations to invoke the nptq command from the shell to query remote devices, organizations can avoid these issues by using ‘-c raw’ options in ntpq invocation from the shell for that specific session when running the command.
“ntpq -c raw <other options>”
Where the “<other options>” includes the IP address of the remote device where the query needs to be sent.
This does not work around these issues and doesn't remediate the risk that an authenticated session with shell access can invoke the ntpq command without these options.
To reduce the risk of exploitation of these issues, restrict users who can access the device shell, and disallow further use of the ntpq command without -c raw as part of operational procedures. Additionally, monitor, alert, and audit for the use of ntpq in the shell as part of operational procedures ongoing.
Further, to reduce the risk of DDoS amplification attacks in general, per ntp.org: "NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to being used in distributed denial-of-service (DDoS) attacks. Please also take this opportunity to defeat denial-of-service attacks by implementing Ingress and Egress filtering through BCP38." Please see the URLs section for further details.
2023-10-11: Initial Publication