Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX Series - EX2200 3300 4200 4500 6210 8208 8216

Alert Description

Junos Software Service Release version 15.1R7-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 15.1R7-S11 is now available.

15.1R7-S11 - List of Fixed issues

PR Number Synopsis Category: Marvell based EX PFE L3
1602259 Legacy EX switch may stop forwarding ARP packets in rare case
Product-Group=junos
On EX2200/EX3300/EX3200/EX4200/EX4500/EX4550 platform, if IGMP Snooping or Proxy ARP is configured, the switch may stop forwarding ARP packets in rare cases.
PR Number Synopsis Category: Security platform jweb support
1594516 Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root. (CVE-2021-31372)
Product-Group=junos
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. Refer to https://kb.juniper.net/JSA11237 [juniper.net] for more information.
PR Number Synopsis Category: Layer2 forwarding on EX/NTF/PTX/QFX
1599094 The l2ald process may crash due to memory leak when all active interfaces in a VLAN are unstable
Product-Group=junos
When none of the constituent active interfaces on a VLAN is stable, memory leak may occur which might eventually lead l2ald to crash. No memory leak will be seen if one or some constituent interfaces are flapping but the VLAN has at least one active stable interface overall.
PR Number Synopsis Category: VSRX platform software
1603199 Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks. (CVE-2021-31386)
Product-Group=junos
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. Refer to https://kb.juniper.net/JSA11254 [juniper.net] for more information.
 

15.1R7-S11 - List of Known issues

PR Number Synopsis Category: Security platform jweb support
1449280 Junos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal (CVE-2021-31355)
Product-Group=junos
A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device; Refer to https://kb.juniper.net/JSA11220 [juniper.net] for more information.
 
 

Modification History

First publication 2021-12-09