Product Affected

These issues affect multiple products.
High

Problem

An Authentication Bypass by Spoofing vulnerability in RADIUS protocol of Juniper Networks Junos OS, Junos OS Evolved, cRPD and other platforms allows an on-path attacker between RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. This vulnerability depends on using the MD5 hash function to pass undetected attribute forgery by modifying RADIUS server Responses (Access-Accept, Access-Reject, or Access-Challenge). The attacker does not learn user credentials.


It primarily impacts RADIUS implementation using non-EAP authentication methods over UDP. RADIUS/TLS (RadSec) is not susceptible as TLS protects against the attacks. A RADIUS client is vulnerable if it does not require a Message-Authenticator attribute in every server response. It requires an online attack to be able to compute chosen-prefix MD5 collision attack in a time less than the configured radius (round-trip) timeout.


Devices that are not configured with Radius Authentication are not affected by this issue. 
 

Vulnerability impact varies based on the mix of infrastructure devices (RADIUS clients), RADIUS servers and protocols implemented as follows:

 

Affected implementations are:

  • Non-EAP based authentications such as PAP / CHAP / MS-CHAP
  • and Communicating over UDP in the clear
  • and Without Message-Authenticator in requests and responses

Unaffected implementations include:

  • EAP based 802.1X Authentications
  • or Protected over TLS such as RadSec
  • or Require Message-Authenticator attribute from every server-client response


For additional information regarding this vulnerability, please see https://blastradius.fail.

 

Based on our current analysis the following products are vulnerable to the issue described in CVE-2024-3596:

  • Juniper Networks Junos OS
    • All versions before 21.4R3-S9,
    • from 22.2 before 22.2R3-S5,
    • from 22.4 before 22.4R3-S5,
    • from 23.2 before 23.2R2-S3,
    • from 23.4 before 23.4R2-S3,
    • from 24.2 before 24.2R2;
  • Juniper Networks Junos OS Evolved
    • All versions before 21.4R3-S9-EVO,
    • from 22.2 before 22.2R3-S5-EVO,
    • from 22.3 before 22.3R3-S4-EVO,
    • from 22.4 before 22.4R3-S5-EVO,
    • from 23.2 before 23.2R2-S3-EVO,
    • from 23.4 before 23.4R2-S3-EVO,
    • from 24.2 before 24.2R2-EVO.
  •  Juniper Networks cRPD
    • 23.4 version and later versions before 23.4R2-S3 
    • from 24.2 before 24.2R2.

     Versions of cRPD prior to 23.4 are unaffected by this vulnerability.


For Mist products and Services:


Based on our current analysis the following Juniper Networks products are not affected by CVE-2024-3596 issue:

  • Juniper Secure Analytics Series 
  • Juniper Identity Management Services (JIMS)
  • SecIntel
  • Paragon Active Assurance



    The following products are under analysis and may be affected by CVE-2024-3596 issue:

    • Juniper Secure Analytics Risk Manager
    • Network and Security Manager (NSM)
    • WANDL IP/MPLSView
    • Advanced Threat Prevention (JATP)
    • Apstra System
    • Contrail products: Contrail Analytics, Contrail Cloud, Contrail Networking or Contrail Service Orchestration
    • Healthbot
    • JATP Cloud
    • Juniper Sky Enterprise
    • Network Director
    • CTPOS and CTPView
    • Security Director Insights
    • Security Director
    • Session Smart Router (Formerly 128T)
    • Space SDK

    We continue to evaluate products and this advisory will be updated as further information becomes available.

    This issue was discovered during external security research.

    This issue has been assigned  CVE-2024-3596.

     

    To be exposed to this issue, RADIUS authentication must be enabled on the device.

    For Junos OS and Junos OS Evolved, the following configuration will enable RADIUS authentication:

    Administrative Access:
          [system radius-server]
          [system authentication-order radius]


    Subscriber Access:
          [access profile <name> radius-server]

     

    Solution

    The following software releases have been updated to resolve this specific issue for RADIUS administrative access

    Junos OS: 21.4R3-S9*, 22.2R3-S5*, 22.4R3-S5*, 23.2R2-S3*, 23.4R2-S3*, 24.2R2*, 24.4R1* and all subsequent releases.

    Junos OS Evolved: 21.4R3-S9-EVO*, 22.2R3-S5-EVO*, 22.4R3-S5-EVO*, 23.2R2-S3-EVO*, 23.4R2-S3-EVO*, 24.2R1-S2-EVO*, 24.2R2-EVO*, 24.4R1-EVO* and all subsequent releases.

    cRPD: 23.4R2-S3*, 24.2R2*, 24.4R1* and all subsequent releases.

    *future release

    Note:  The fix for RADIUS subscriber access is published as a separate JSA100056 [juniper.net].
     

    This issue is being tracked as 1802329, 1826678 and 1850776 which are visible on the Customer Support website.

    Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

    Workaround

    Enabling RADIUS over TLS (RADSEC) will mitigate this issue. RADIUS clients and servers configured to use DTLS or TLS over TCP are not exploitable, even if the underlying implementation is otherwise vulnerable, as long as the traffic is not sent in plaintext.

    Severity Assessment

    Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

    Modification History

    • 2024-09-30: Initial Publication
    • 2024-10-01: Corrected CVSS v4.0 score
    • 2024-10-03: Modified Workaround and added Acknowledgements
    • 2024-10-16: changed cRPD affected version from "23.4R3-S5" to "23.4R2-S3"
    • 2024-10-30: Added Junos OS and Junos OS Evolved Radius authentication config and note on separate PR for Radius Subscriber access
    2025-07-15: Added the JSA100056 for Radius Subscriber access

    Related Information

    Acknowledgements

    This vulnerability was publicly disclosed by Sharon Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl.