Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

Junos 19.1R3 FIPS and respective SRs for EX2300, EX3400, MX240-960, MX104, EX9200

Alert Description

Junos Software Service Release version 19.1R3-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.1R3-S11 is now available.

19.1R3-S11 - List of Fixed issues 

PR NumberSynopsisCategory: BBE database related issues
1346925Statistics daemon PFED may core on an upgrade between certain releases
Product-Group=junos
On any platform that does not clear out /mfs when installing a new software release such as EX/QFX, when upgrading from certain releases to 18.1R1 the statistics daemon PFED may core dump. This issue is not service impacting.
1348727The authd and bbe-smgd processes might crash due to a rare timing and scaling issue
Product-Group=junos
From 15.1 onwards, in subscriber environment, the authd and bbe-smgd process crashes might be seen due to a rare timing and scaling issue.
1351203The pfed process might consume high CPU if subscriber or interface statistics are used at large scale
Product-Group=junos
If subscriber or interface statistics are used at large scale (thousands or more), the pfed process might consume high CPU due to a low performance code processing. It applies on all platforms but this issue was mainly observed on PPC based routers (such as MX104) when large-scale subscribers (such as 8k) log in with subscriber management environment and accounting is turned on.
PR NumberSynopsisCategory: BBE interface related issues
1734564Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75725 [juniper.net] for more information.
PR NumberSynopsisCategory: BBE state synchronization issues
1380231The Routing Engines might crash with various core files due to the deadlock issue on the SDB STS
Product-Group=junos
In the system that uses session database (SDB), the deadlock might happen when getting the lock on the SDB short term storage (STS) due to a rare timing issue. It is more likely to happen on Enhanced Subscriber Management environment with large-scale subscribers (such as 50k subscribers). The issue will cause the master Routing Engine (RE) to crash with various core files and lose the management connectivity. And the subscriber service could be affected. The issue might happen on single RE system as well as dual RE system. In the dual RE system, the master RE crash could trigger a RE switchover. But the issue could cause the incomplete state on the SDB in the new master RE, which could cause the subscribers login failure. A restart of smg-service on the new master RE will recover this login issue.
PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1736029Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor (CVE-2023-44186)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73150 [juniper.net] for more information.
1739919Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71542 [juniper.net] for more details.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1336388Subscriber might experience SDB DOWN event and drop the clients' connections when issuing "show subscribers" commands
Product-Group=junos
In Subscriber environment, when issuing a large number (>10) of "show subscribers" commands concurrently on a light-to-medium loaded system, the Session Database (SDB) down event might be observed and the client connections might be dropped.
PR NumberSynopsisCategory: Express PFE FW Features
1716398Junos OS: PTX Series and QFX10000 Series: Received flow-routes which aren't installed as the hardware doesn't support them, lead to an FPC heap memory leak (CVE-2023-22392)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73530 [juniper.net] for more information.
PR NumberSynopsisCategory: jdhcpd daemon
1706709Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75730 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Network Address Translation
1702811Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75757 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Policy
1694960Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash (CVE-2024-21594)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75733 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1735389Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1747984Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/JSA75729 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 Control Module
1712287Junos OS and Junos OS Evolved: An l2cpd crash will occur when specific LLDP packets are received (CVE-2023-36839)
Product-Group=junos
An Improper Validation of a Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial of Service(DoS). Please refer to https://supportportal.juniper.net/JSA73171 [juniper.net] for more information.
1763053LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: PTX1000 platform
1653316Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition (CVE-2024-21600)
Product-Group=junos
An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75741 [juniper.net] for more information.
PR NumberSynopsisCategory: Kernel socket data replication issues for protocols that use
1711656Junos OS: BGP flap on NSR-enabled devices causes memory leak (CVE-2024-21617)
Product-Group=junos
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75758 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to PKI daemon
1694604IPSEC tunnel is not getting established back after the execution of 'clear security ike sa'
Product-Group=junos
On Junos SRX platforms, the IPSEC (Internet Protocol Security) tunnels do not get established after the tunnels are deleted using the command 'clear security ike sa'.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1738548DHCP offer is dropped at MX and specific EX platforms when an lt interface is used as the transport
Product-Group=junos
On MX and EX92_XX platforms, the DHCP offer will be dropped when LT interface is used to reach the DHCP server. DHCP relay will not work as expected due to this issue.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1670797Junos OS: MX Series: Gathering statistics in a scaled SCU/DCU configuration will lead to a device crash (CVE-2024-21603)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service. Please refer to https://supportportal.juniper.net/JSA75744 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX RCB issues
1763588Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
 
 

19.1R3-S11 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1742303DHCP packets traversing the switch even though the source mac is not present in accept-source-mac list
Product-Group=junos
In EX2300 & EX3400 devices, even though accept-source-mac knob is configured, DHCP Packets with the MAC address not present in the accept-source-mac list are accepted and traverse in the network.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4
PR NumberSynopsisCategory: EX2300/3400 platform
PR NumberSynopsisCategory: Border Gateway Protocol
1626717Junos OS and Junos OS Evolved: An rpd crash may occur when BGP is processing newly learned routes (CVE-2023-44197)
Product-Group=junos
An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73163 [juniper.net] for more information.

Resolved In: evo:20.4R3-S8-EVO evo:20.4X6-EVO evo:21.2R3-S2-EVO evo:21.4R2-S1-EVO evo:21.4R3-S5-EVO evo:21.4X1-EVO evo:22.1R1-EVO evo:22.2R1-EVO junos:19.2R3-S8 junos:19.3R3-S8 junos:19.4R3-S12 junos:20.3X75-D36 junos:20.3X75-D40 junos:20.4R3-S8 junos:21.2R3-S2 junos:21.3R3-S5 junos:21.4R2-S1 junos:21.4R3-S5 junos:22.1R1 junos:22.2R1
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Security platform jweb support
1698386Junos OS: J-Web: Multiple Vulnerabilities in PHP software
Product-Group=junos
PHP software included with Junos OS J-Web has been updated from 7.4.30 to 8.2.0 to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA71653 [juniper.net] for more information.

Resolved In: evo:23.2R1-EVO evo:23.3R1-EVO junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1669322Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS).

Resolved In: evo:21.4R3-EVO evo:22.1R2-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO evo:22.4R1-EVO junos:19.3R3-S2-J1 junos:19.4R3-S9 junos:20.3R3-S5 junos:20.3X75-D35 junos:20.3X75-D42 junos:21.2R3-S1 junos:21.2R3-S2 junos:21.2X32-D10 junos:21.3R3-S1 junos:21.4R3 junos:22.1R2 junos:22.1R3 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: DHCP related Issues
1711644QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging (CVE-2023-44191)
Product-Group=junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73155 [juniper.net] for more information.

Resolved In: junos:21.2R3-S5 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1667069Junos OS: QFX5000 series, EX2300, EX3400, EX4100, EX4400, and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN (CVE-2023-44203)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73169 [juniper.net] for more information.

Resolved In: junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S2 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1721936Junos OS: SRX Series: flowd will crash when "tcp-encap" is enabled and specific packets are received (CVE-2024-21606)
Product-Group=junos
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75747 [juniper.net] for more information.

Resolved In: junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1668419Junos OS: MX Series: An FPC crash is observed when CFM is enabled in a VPLS scenario and a specific LDP related command is run (CVE-2023-44193)
Product-Group=junos
An Improper Release of Memory Before Removing the Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, low-privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73157 [juniper.net] for more information.

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.4R3-S12 junos:20.2R3-S7 junos:20.3X75-D46 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.1R3-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1732283Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=junos
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/JSA73153 [juniper.net] for more information.

Resolved In: evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1

Modification History

First publication 2024-01-18