Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX Series

Alert Description

Junos Software Service Release version 12.3R12-S20 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 12.3R12-S20 is now available.

12.3R12-S20 - List of Fixed issues
PR Number Synopsis Category: QFX L2 Protocols Control Plane related
1169252 The l2cpd process might crash with core dump when description of an interconnect interface on a LLDP neighbor is long greater than 32 chars
Product-Group=junos
When enable LLDP and interface description is long(greater that 32 chars) on remote switch, the l2cpd (Layer 2 Control Protocol process) might crash with core dump if performing SNMP MIB walk since LLDP code is running within l2cpd.
PR Number Synopsis Category: Security platform jweb support
1594516 Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root. (CVE-2021-31372)
Product-Group=junos
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. Refer to https://kb.juniper.net/JSA11237 [juniper.net] for more information.
PR Number Synopsis Category: VSRX platform software
1603199 Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks. (CVE-2021-31386)
Product-Group=junos
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. Refer to https://kb.juniper.net/JSA11254 [juniper.net] for more information.
 

Modification History

First publication 2021-12-21