Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX204, NFX150, SRX family except for SRX380, SRX345, and SRX1500

Alert Description

Junos FIPS Software Service Release version 19.2R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box (only applicable to JUNOS FIPS on MX204, NFX150, SRX family except for SRX380, SRX345, and SRX1500)
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

Solution

unos Software service Release version 19.2R3-S7 is now available.

19.2R3-S7 - List of Fixed issues 

PR NumberSynopsisCategory: BBE interface related issues
1681389Junos OS: MX Series: In a BBE scenario upon receipt of specific malformed packets from subscribers the process bbe-smgd will crash (CVE-2023-28974)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA70599 [juniper.net] for more information.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1619359Junos OS: QFX10002: Failure of storm control feature may lead to Denial of Service (CVE-2023-28965)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Please refer to https://supportportal.juniper.net/JSA70589 [juniper.net] for more information.
1667678Junos OS: QFX10000 Series, PTX1000 Series: The dcpfe process will crash when a malformed ethernet frame is received (CVE-2023-1697)
Product-Group=junos
An Improper Handling of Missing Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a dcpfe process core and thereby a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA70612 [juniper.net] for more information.
1686793Junos OS: QFX10002: PFE wedges and restarts upon receipt of specific malformed packets (CVE-2023-28959)
Product-Group=junos
QFX10002 allows an unauthenticated, adjacent attacker on the local broadcast domain sending a malformed packet to the device, causing all PFEs other than the inbound PFE to wedge and to eventually restart, resulting in a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA70584 [juniper.net] for more information
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.
PR NumberSynopsisCategory: Firewall Policy
1694222Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open (CVE-2023-28968)
Product-Group=junos
An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through. Please refer to https://supportportal.juniper.net/JSA70592 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1698072Junos OS: Multiple vulnerabilities in J-Web(CVE-2023-28962)
Product-Group=junos
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. Please refer to https://supportportal.juniper.net/JSA70587 [juniper.net] for more information.
1698075Junos OS: Multiple vulnerabilities in J-Web (CVE-2023-28963)
Product-Group=junos
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. Please refer to https://supportportal.juniper.net/JSA70587 [juniper.net] for more information.
PR NumberSynopsisCategory: lacp protocol
1609618LACP Member interfaces might get stuck in out of sync state.
Product-Group=junos
When sync-reset feature is enabled on the device then few member interfaces might stay in out of sync state even when number of available child interfaces is greater than minimum-links configured for the Lag interface. This will affect the overall capacity of the lag interface .
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1669072Junos OS: NFX Series: 'set system ports console insecure' allows root password recovery (CVE-2023-28972)
Product-Group=junos
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. Please refer to https://supportportal.juniper.net/JSA70596 [juniper.net] for more information.
1681783On Ex4400 upgrade failure happens when upgrading through a USB drive.
Product-Group=junos
On EX4400 upgrade failure happens when upgrading through a USB drive.
1688079Junos OS: Multiple vulnerabilities in expat resolved
Product-Group=junos
Multiple vulnerabilities in the third party software component expat have been resolved. Please refer to https://supportportal.juniper.net/JSA70605 [juniper.net] for more information.
1704032VM process crashes if a file is shared between the host operating system and the guest operating system using virtFS
Product-Group=junos
On Virtual Machines (VM) based platforms running Junos images, files are not shared between the host operating system and guest operating system via Virtual Filesystem (virtFS). When this issue happens, the device will be restarted.
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1662400Junos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check fails (CVE-2023-28979)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity check. Please refer to https://supportportal.juniper.net/JSA70604 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX L2 PFE
1666224Junos OS: QFX Series: The PFE may crash when a lot of MAC addresses are being learned and aged (CVE-2023-28984)
Product-Group=junos
A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA70610 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX branch platforms
1638519Junos OS: The kernel will crash when certain USB devices are inserted (CVE-2023-28975)
Product-Group=junos
An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA70600 [juniper.net] for more information.
PR NumberSynopsisCategory: Trio pfe qos software
1681162The MPC crashes when interfaces move in and out from an AE bundle or subscribers log in and out
Product-Group=junos
This issue occurs on Junos MX Series routers in a scaled setup when the physical interface (IFD) moves in and out from an aggregated Ethernet bundle or subscribers log in and out before the subscriber was cleaned up. This triggers high CPU usage followed by a Modular Port Concentrator (MPC) crash. It impacts the data traffic.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1647532Junos OS: MX Series: If a specific traffic rate goes above the DDoS threshold leads to an FPC crash (CVE-2023-28976)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA70601 [juniper.net] for more information.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1717425Junos platform device unable to commit configuration in recovery mode
Product-Group=junos
On all Junos platforms where snapshot is supported, when a device is rebooted from recovery mode it fails to commit configuration due to problems with slax import and device might go into amnesiac mode due commit fail.
PR NumberSynopsisCategory: Issues related to all UI tools (mgd-bsd/cli-bsd, XML and DMI
1681656System uptime display is shown in minutes instead of seconds
Product-Group=junos
On all Junos and Junos Evolved platforms, after the device reboot, show system uptime command is showing time in minutes instead of seconds for 24 hours.
 
 

19.2R3-S7 - List of Known issues 

PR NumberSynopsisCategory: Firewall support for DNX
1653475Junos OS: ACX Series: IPv6 firewall filter is not installed in PFE when "from next-header ah" is used (CVE-2023-28961)
Product-Group=junos
An Improper Handling of Unexpected Data Type vulnerability in IPv6 firewall filter processing of Juniper Networks Junos OS on the ACX Series devices will prevent the firewall filter term 'from next-header ah' from being properly installed in the packet forwarding engine (PFE). There is no immediate indication of an incomplete firewall filter commit shown at the CLI, which could allow an attacker to send valid packets to or through the device that were explicitly intended to be dropped. https://supportportal.juniper.net/JSA70586 [juniper.net] for more information.

Resolved In: junos:20.2R3-S7 junos:20.4R3-S4 junos:21.1R3-S3 junos:21.2R3-S4 junos:21.3R3 junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: vMX Data Plane Issues
1669261vMX crashes due to MBUF leaks
Product-Group=junos
vMX platforms (MX150) will crash as a result of the MBUF (Memory Buffer) leak.

Resolved In: junos:20.3X75-D43 junos:20.3X75-D46 junos:20.4R3-S5 junos:21.4R3 junos:22.1R3 junos:22.3R1 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: JRR - VRR running on SRX4200
1677503Junos OS: JRR200: Kernel crash upon receipt of a specific packet (CVE-2023-28970)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the device to cause a kernel crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA70594 [juniper.net] for more information.

Resolved In: junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R2-S2 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S1 junos:22.4R2 junos:23.1R1

Modification History

First publication 2023-06-10