Multiple vulnerabilities have been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved by upgrading net-SNMP to version 5.9.4, or by fixing vulnerabilities found during internal testing.
For CVE-2015-5621 and CVE-2008-6123 :These issues affect Junos OS:
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered by a third-party upstream provider.
The following software releases have been updated to resolve these specific issues:Junos OS: 21.2R3-S8, 21.4R3-S7, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2, 23.4R1-S1, 23.4R2, 24.2R1, and all subsequent releases.Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-EVO, 23.4R1-S1-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.For CVE-2019-20892, CVE-2012-6151, and CVE-2007-5846 these fixes are already present in End of Engineering support software and therefore listed as resolved and not affecting engineering-supported software.For CVE-2020-15861, CVE-2020-15862, CVE-2019-20892, CVE-2018-18065, CVE-2015-8100, CVE-2014-3565, CVE-2014-2310, and CVE-2014-2285 these issues do not affect Junos OS or Junos OS Evolved and are included as resolved.These issues are being tracked as 1775593 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no workarounds for these issues.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to Junos OS and Junos OS Evolved to only trusted administrative networks, hosts, and users.
2024-07-10: Initial Publication 2024-09-13: Minor formatting change to CVSS field