These issues affect:
Junos OS:
Important security issues resolved include:
6.4 Medium
5.7 Medium
Junos OS:CVE-2023-38545 - The SOCKS5 service is not implemented in Junos OS. Further, Junos OS provides VERIEXEC protection to natively protect against the exploitation of this vulnerability. Such an attack would likely follow a chaining pattern, where the attacker first leverages a separate method of exploitation to infiltrate the device. A successful attack against Junos OS would probably demand elevated privileges, shell access, and the ability to circumvent VERIEXEC.CVE-2023-23914 - A successful attack against Junos OS would probably demand elevated privileges and shell access.CVE-2023-23915 - A successful attack against Junos OS would probably demand elevated privileges and shell access.CVE-2020-8284 - A successful attack against Junos OS would probably demand elevated privileges and shell access.CVE-2020-8285 - Junos OS does not use this option. A successful attack against Junos OS would probably demand elevated privileges and shell access.CVE-2020-8286 - Junos OS does not use this option. Such an attack would likely follow a chaining pattern, and even then the attacker must breach a TLS server and then provide a fraudulent OCSP response that would appear genuine to the target device. A successful attack against Junos OS would probably demand elevated privileges and shell access.Junos OS Evolved:CVE-2018-1000120 - A successful attack against the device would probably demand elevated privileges and shell access and additional advanced attack methods to bypass these built-in security controls.CVE-2018-1000122 - A successful attacker would have to leverage a malicious RSTP server and would probably demand elevated privileges and shell access.
The following software releases have been updated to resolve these specific issues:
Junos OS: 21.2R3-S8, 21.4R3-S8, 23.4R1-S1, 23.4R2, 24.2R1, and subsequent releases.Note for Junos OS: For CVE-2018-1000120 and CVE-2018-1000122 see JSA10874 [juniper.net]. These CVEs are already resolved in earlier releases of Junos OS, they are included in this advisory for Junos OS Evolved only.
Junos OS Evolved: 21.4R3-S4-EVO, 22.1R3-S4-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 23.2R1-EVO, and subsequent releases.Note for Junos OS Evolved: CVE-2023-38545 and CVE-2023-38546 Junos OS Evolved is not vulnerable to these CVEs.
These issues are being tracked as 1769149, 1723054, 1562153 and 1347361 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.To reduce the risk of exploitation of these issues: