CVSS: v3.1: 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
The OpenSSL project has published security advisories for multiple vulnerabilities.
These issues affect Junos OS:
These issues do not affect versions of Junos OS prior to 21.2.
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered by a third-party upstream provider.
The following software releases have been updated to resolve these specific issues: 21.4R3-S8, 21.4R3-S9, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2, 24.4R1*, and all subsequent releases.*Future release
These issues are being tracked as 1815253 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue may include:
2024-10-09: Initial Publication