Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
SRN Notification
Impact
Impact Description
Low/Notification
SRN Notification
Product Affected
EX-Series
Alert Description
Junos Software Service Release Notification for version 12.3R12-S21
Junos Software Service Release version 12.3R12-S21 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Solution
Junos Software service Release version 12.3R12-S21 is now available.
12.3R12-S21 - List of Fixed issues
PR Number
Synopsis
Category: QFX Access Control related
893630
Dot1x username greater than 50 characters are not authenticating successfully.
Product-Group=junos
Dot1x username has been increased to 63 characters.
12.3R12-S21 - List of Known issues
PR Number
Synopsis
Category: OSPF routing protocol
1599491
Junos OS and Junos OS Evolved: OSPFv3 session might go into INIT state upon receipt of multiple crafted packets from a trusted neighbor device. (CVE-2022-22169)
Product-Group=junos
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any Grace-LSA received in OSPFv3 causing a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11276
[juniper.net]
for more information.
PR Number
Synopsis
Category: Junos Automation, Commit/Op/Event and SLAX
1542229
Junos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URL (CVE-2022-22156)
Product-Group=junos
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of the device. Refer to https://kb.juniper.net/
JSA11264
[juniper.net]
for more information.
Modification History
First publication 2022-04-07
12.3R12-S21: Software Release Notification for JUNOS Software Version 12.3R12-S21