Alert Type

SRN - Software Release Notification
Low/NotificationSRN Notification
Low/NotificationSRN Notification

Product Affected

EX-Series

Alert Description

Junos Software Service Release Notification for version 12.3R12-S21

Junos Software Service Release version 12.3R12-S21 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Solution

Junos Software service Release version 12.3R12-S21 is now available.

12.3R12-S21 - List of Fixed issues

PR NumberSynopsisCategory: QFX Access Control related
893630Dot1x username greater than 50 characters are not authenticating successfully.
Product-Group=junos
Dot1x username has been increased to 63 characters.
 
 

12.3R12-S21 - List of Known issues

PR NumberSynopsisCategory: OSPF routing protocol
1599491Junos OS and Junos OS Evolved: OSPFv3 session might go into INIT state upon receipt of multiple crafted packets from a trusted neighbor device. (CVE-2022-22169)
Product-Group=junos
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any Grace-LSA received in OSPFv3 causing a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11276 [juniper.net] for more information.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1542229Junos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URL (CVE-2022-22156)
Product-Group=junos
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of the device. Refer to https://kb.juniper.net/JSA11264 [juniper.net] for more information.

Modification History

First publication 2022-04-07