The OpenSSL project has published security advisories for multiple vulnerabilities resolved in OpenSSL 3.0.12.These issues affect Juniper Networks Junos OS Evolved:
Important security issues resolved are described below:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered by a third-party upstream provider.
The following software releases have been updated to resolve this specific issue: 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.
These issues are being tracked as 1770952 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Since SSL is used for remote network configuration and management applications such as SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue may include:
In addition to the recommendations listed above, it is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device only from trusted, administrative networks or hosts.
2024-07-10: Initial Publication 2024-09-13: Minor formatting change to CVSS field