Description

What is the process and schedule used by the Juniper Networks SIRT for disclosing information to customers regarding vulnerability-related issues?

Symptoms

Improve support by publishing Juniper Security Advisories and Security Notices to customers on a deterministic, periodic basis.

Solution

The Juniper Networks Security Incident Response Team (Juniper SIRT) constrains the publication of Juniper Security Advisories for non-urgent issues to a predefined quarterly schedule of the second Wednesday of January, April, July, and October, covering all Juniper products.

In exceptional circumstances, the Juniper SIRT may publish an out-of-cycle Security Advisory, but that is intended to be a rare event. Examples include, but are not limited to, active malicious exploitation of a zero-day Juniper vulnerability or perhaps a multi-vendor issue in which all participating parties must publish simultaneously on a schedule negotiated by an external coordinating agency.

 

Two other types of Security Advisories published by the Juniper SIRT are:

 

  • Reference Advisories: Published in response to multiple customer inquiries. Generally referenced by JTAC or from within another Juniper Security Advisory
  • On-Demand Advisories: Published on-demand, as needed, for our more agile products, such as AppFormix and Secure Analytics. Also used for coordinated vulnerability disclosure with third parties, such as IBM QRadar.


The Juniper SIRT considers numerous criteria for determining if an issue warrants SIRT attention and, if so, how and to what range of products and software releases a fix will be applied and how and when the issue will be published. The Juniper SIRT uses the Common Vulnerability Scoring System (CVSS) to rank an issue as one factor in its evaluation. Information for how Juniper Networks uses CVSS can be found in KB16446 [juniper.net] in the  Related Information section below.

The Related Information section below also provides more information about the Juniper SIRT, including methods for reporting a product security vulnerability.
 

Modification History

2015-12-28: Initial Publication
2022-10-28: Added link to Security Advisory list
2025-03-13: Included references to On-Demand and Reference advisories
2026-07-10: Updated link to Security Advisory list.

Related Information