Product Affected

This issue affects Junos OS 21.2, 21.4, 22.2, 22.3, 22.4, 23.2, 23.4, 24.2.
Medium

CVSS: v3.1: 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Problem

The ​OpenSSL project has published security advisories for multiple vulnerabilities.

 

These issues affect Junos OS: 

  • All versions of 21.2,
  • 21.4 before 21.4R3-S8, 
  • 22.2 before 22.2R3-S5, 
  • 22.3 before 22.3R3-S4, 
  • 22.4 before 22.4R3-S3, 
  • 23.2 before 23.2R2-S2, 
  • 23.4 before 23.4R2-S1, 
  • 24.2 before 24.2R1-S1, 24.2R2.

These issues do not affect versions of Junos OS prior to 21.2.

 

Important security issues resolved include:

CVECVSSSummary
CVE-2024-47415.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.
CVE-2024-25113.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) A vulnerability was found in OpenSSL where a malicious client can trigger an uncontrolled memory consumption, resulting in a Denial of Service. This issue occurs due to OpenSSL's TLSv3.1 session cache going into an incorrect state, leading to it failing to flush properly as it fills. OpenSSL must be configured with the non-default SSL_OP_NO_TICKET option enabled to be vulnerable. This issue only affects TLSv1.3 servers, while TLS clients are not affected.

 

Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.

These issues were discovered by a third-party upstream provider.

Solution

The following software releases have been updated to resolve these specific issues: 21.4R3-S8, 21.4R3-S9, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2, 24.4R1*, and all subsequent releases.
*Future release

 

These issues are being tracked as 1815253 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue may include:

  • Disabling J-Web
  • Disable SSL service for Junos XML management and only use Netconf, which makes use of SSH, to make configuration changes
  • Limit access to J-Web and XNM-SSL from only trusted networks

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2024-10-09: Initial Publication

Related Information