Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX2200, EX4200, EX4500, EX4550, EX8208, EX8216

Alert Description

Junos Software Service Release version 15.1R7-S13 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 15.1R7-S13 is now available.

15.1R7-S13 - List of Fixed issues

PR NumberSynopsisCategory: EX Marvell Platform related Issues
1659762Interface flap on EX4500/4550 with SFP-T module without connecting a cable.
Product-Group=junos
Interface might go flapping occasionally on EX4500 or EX4550 with SFP-T module without connecting a cable.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacpl
1604157Junos OS and Junos OS Evolved: /var/run/.env files are potentially not deleted during termination of a gRPC connection causing inode exhaustion (CVE-2022-22215)
Product-Group=junos
A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Please refer https://kb.juniper.net/JSA69719 [juniper.net] for more information.
 
 

15.1R7-S13 - List of Known issues

PR NumberSynopsisCategory: OpenSSL and related subsystems
1618986Junos OS: OpenSSL security fixes
Product-Group=junos
Juniper Networks has upgraded the OpenSSL library included in Juniper Networks Junos OS to fix specific vulnerabilities. Please refer to https://kb.juniper.net/JSA69715 [juniper.net] for more information.
PR NumberSynopsisCategory: Signature Database
1583420Junos OS and Junos OS Evolved: Multiple vulnerabilities in SQLite resolved
Product-Group=junos
Multiple vulnerabilities in SQLite as used in Juniper Networks Junos OS and Junos OS Evolved have been resolved by upgrading SQLite from 3.31.1 to 3.37.0. Services that rely upon SQLite are the Connectivity Fault Management (CFM) Daemon (CFDM), AppID, IDP, Apache2, J-Web, and JSQL as used by IPID, SecIntel Threat Intelligence, useridd, accounts, processes and services. Refer to https://kb.juniper.net/JSA69705 [juniper.net] for more information.
PR NumberSynopsisCategory: slt security platform jweb support
1591621Junos OS: J-Web can be compromised through reflected XSS attacks (CVE-2022-22181)
Product-Group=junos
A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. Refer to https://kb.juniper.net/JSA69517 [juniper.net] for more information.

Modification History

First publication 2022-08-30