Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
EX Series - EX2200 3300 4200 4500 6210 8208 8216
Alert Description
Junos Software Service Release version 15.1R7-S11 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 15.1R7-S11 is now available.
15.1R7-S11 - List of Fixed issues
PR Number
Synopsis
Category: Marvell based EX PFE L3
1602259
Legacy EX switch may stop forwarding ARP packets in rare case
Product-Group=junos
On EX2200/EX3300/EX3200/EX4200/EX4500/EX4550 platform, if IGMP Snooping or Proxy ARP is configured, the switch may stop forwarding ARP packets in rare cases.
PR Number
Synopsis
Category: Security platform jweb support
1594516
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root. (CVE-2021-31372)
Product-Group=junos
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. Refer to https://kb.juniper.net/
JSA11237
[juniper.net]
for more information.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1599094
The l2ald process may crash due to memory leak when all active interfaces in a VLAN are unstable
Product-Group=junos
When none of the constituent active interfaces on a VLAN is stable, memory leak may occur which might eventually lead l2ald to crash. No memory leak will be seen if one or some constituent interfaces are flapping but the VLAN has at least one active stable interface overall.
PR Number
Synopsis
Category: VSRX platform software
1603199
Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks. (CVE-2021-31386)
Product-Group=junos
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. Refer to https://kb.juniper.net/
JSA11254
[juniper.net]
for more information.
15.1R7-S11 - List of Known issues
PR Number
Synopsis
Category: Security platform jweb support
1449280
Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal (CVE-2021-31355)
Product-Group=junos
A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device; Refer to https://kb.juniper.net/
JSA11220
[juniper.net]
for more information.
Modification History
First publication 2021-12-09
15.1R7-S11: Software Release Notification for JUNOS Software Version 15.1R7-S11