Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

This software release is for EX4300-48MP in FIPS mode. See TSB70153 [juniper.net]

Alert Description

Junos Software Service Release version 19.4R3-S13 is now available for download from the Junos software download site. This software release is for EX4300-48MP in FIPS mode. See TSB70153 [juniper.net]

Solution

unos Software service Release version 19.4R3-S13 is now available.

19.4R3-S13 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 Platform implementation
1499771A master RE reconnect might be seen on EX4300-48MP platform
Product-Group=junosvae
On EX4300-48MP platform, if POE is enabled, a master RE reconnect might be seen which could cause traffic impact.
PR NumberSynopsisCategory: EX2300/3400 platform
PR NumberSynopsisCategory: SRX Gen-3 RE, leveraged from Point Success Mt.Rainier
1774760RE switchover observed in SRX5K platforms when ethernet switchports failure scenario on SCB
Product-Group=junos
On SRX5K platforms when all ethernet switch ports on Switch Control Board(SCB) fail, it triggers the Routing Engine (RE) switch over and RE0 is stuck in "Disabled" state. As RE0 is disabled and RE1 does have the functionality to coordinate chassis. No PIC will turn up which were failed and triggered the failover and traffic impact will be there for those particular ports and the complete service impact will be there if RE1 had any issue when RE0 is in disable state. RE0 did not recover by its own from the disabled state until manual reboot is done.
PR NumberSynopsisCategory: dynamic vlan creation and associated processing
1743903If more than 32 vlan ranges are configured under the dynamic-profile then login issue and traffic impact can be seen with subscribers of random VLANs
Product-Group=junos
On all Junos platforms that support subscriber services, when more than 32 VLAN ranges are configured, random VLAN (Virtual Local Area Network) traffic is impacted and subscribers are unable to login.
PR NumberSynopsisCategory: BBE interface related issues
1734564Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75725 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1736029Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor (CVE-2023-44186)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73150 [juniper.net] for more information.
1739919Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71542 [juniper.net] for more details.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
1775548The rpd crash can be seen with a scaled BGP sharding setup
Product-Group=junos
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) crash can be seen in scaled setup. The issue will be seen in the BGP (Border Gateway Protocol) RIB (Routing Information Base) sharding scenario. This issue is very unlikely to be encountered.
1779533RPD crash is observed on Junos and Junos Evolved platforms in Route reflector scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, RPD (Routing Protocol Daemon) crash can be seen in BGP-multipath scenario if it has more than 512 routes. The RPD crash will cause a traffic drop but the system will self-recover.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Firewall Filter
1697959Deactivating and activating the GRES causes churn in dfwd filter addition/deletion
Product-Group=junos
On all Junos dual-RE platforms, when performing activate/deactivate Graceful Routing Engine Switchover (GRES) multiple times synchronization issues are observed between the master and backup dfwd process.
1749092High CPU utilization of the mib2d process will be observed with error messages due to stale SNMP requests
Product-Group=junos
On all Junos platforms, high CPU utilization, up to 100%, of the mib2d process will be observed with error messages and this may also result in a crash/core when memory gets exhausted due to a gradual increase in stale SNMP (Simple Network Management Protocol) requests.
PR NumberSynopsisCategory: EX4400 PFE software
1733365Error logs are seen with a non-vxlan dot1x enabled port
Product-Group=junos
In a heaviliy loaded system in a specific scenario (Dot1x in multiple supplicant mode & dynamic vlan from radius server & non vxlan access port) following log message may be captured in the syslog - {brcm_as_dot1x_vxlan_set_mac_learning_mode:1168 dot1x bd_get failed for bd index 0}. This log is not impacting any funtionality.
PR NumberSynopsisCategory: track re issu control procedure bugs
1740744ISSU doesn't break if INDB crashes
Product-Group=junos
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.
PR NumberSynopsisCategory: jdhcpd daemon
1706709Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75730 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to Junos Kernel Debug Streaming Daemon (jkdsd
1734718Junos OS: jkdsd crash due to multiple telemetry requests (CVE-2023-44188)
Product-Group=junos
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of Service (DoS). Continued receipt and processing of telemetry requests will repeatedly crash the jkdsd process and sustain the Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA73152 [juniper.net] for more information.
PR NumberSynopsisCategory: Flow Module
1704623Core dump will be seen when user is changing interface configuration
Product-Group=junos
On SRX platforms with ALG (Application Layer Gateways) configured, frequent interface configuration changes will generate one or more core dumps after the flowd process crashes.
PR NumberSynopsisCategory: Firewall Network Address Translation
1702811Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75757 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Policy
1694960Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash (CVE-2024-21594)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75733 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1735389Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1747984Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/JSA75729 [juniper.net] for more information.
1763260Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information (CVE-2024-21619)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
1779376Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS (CVE-2024-21620)
Product-Group=junos
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 VPN related issues
1751717In MPLS-L2VPN/BGP-VPLS setup the flow-label route update is not propagating to neighbouring devices
Product-Group=junos
On all Junos and Junos Evolved platforms where Multi-protocol Label Switching Layer 2 Virtual Private Network (MPLS-L2VPN)/Border Gateway Protocol (BGP) Virtual Private LAN Service (BGP-VPLS) is configured, due to a logical issue with resetting the flow-label config change flag, the flow-label route gets updated only on the first local site in the routing instance and and the route change for remaining local site in that routing instance were not propagated to the neighbouring devices.
PR NumberSynopsisCategory: Layer 2 Control Module
1712287Junos OS and Junos OS Evolved: An l2cpd crash will occur when specific LLDP packets are received (CVE-2023-36839)
Product-Group=junos
An Improper Validation of a Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial of Service(DoS). Please refer to https://supportportal.juniper.net/JSA73171 [juniper.net] for more information.
1763053LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1678431Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash (CVE-2024-21613)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75754 [juniper.net] for more information.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1722708ksyncd core with dhcp subscribers
Product-Group=junos
On all Junos platforms, in a very rare scenario, when subscriber-management and NSR is enabled, there could be a temporary transition state where one subscriber prefix has 2 nexthop referred. In that state if a deletion happened for that particular prefix, the nexthop deletion is successfully done one master RE but the deletion is failed on the backup RE. This eventually causes nh index inconsistency and then ksyncd core on backup RE. The fix is to make sure the deletion on the backup can be done successfully.
1752151The ksyncd process crashes with replication error after performing restart routing
Product-Group=junos
On Junos platforms with dual RE (Routing Engine), VRRP (Virtual Router Redundancy Protocol) configuration, GRES (Graceful Routing Engine Switchover) and NSR (Non-Stop Routing) enabled, ksyncd (Kernel Synchronization Daemon) process will crash post performing routing restart or rebooting master RE. This ksyncd process crash happens due to replication error on backup RE and will recover on its own. There will be no service impact on master RE.
PR NumberSynopsisCategory: Kernel socket data replication issues for protocols that use
1711656Junos OS: BGP flap on NSR-enabled devices causes memory leak (CVE-2024-21617)
Product-Group=junos
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75758 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to PKI daemon
1694604IPSEC tunnel is not getting established back after the execution of 'clear security ike sa'
Product-Group=junos
On Junos SRX platforms, the IPSEC (Internet Protocol Security) tunnels do not get established after the tunnels are deleted using the command 'clear security ike sa'.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1729067Traffic loss will be observed due to CRC errors with QSFP+-40G-ACU10M plugged
Product-Group=junos
On QFX5K platforms with QSFP+-40G-ACU10M and Virtual Chassis configured, traffic loss will be observed due to CRC (Cyclic redundancy check) errors.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1774975Features utilizing inactive routes will not work properly after the device reboot
Product-Group=junos
On all Junos and Junos OS Evolved platforms, due to some software issue, after the device reboot features utilizing inactive routes in the routing table will not work properly. This will cause issues like some inactive routes not being advertised when selected as the best path, features like advertise-inactive not working properly as it utilizes an inactive route flash, high Routing Protocol Daemon (rpd) Central Processing Unit (CPU) utilization, etc.
PR NumberSynopsisCategory: SRX Argon module
1540979SkyATP CLI enrollment fails with the error message "Wrong usage" if company name has a space
Product-Group=junos
On SRX platforms with Sky Advanced Threat Prevention (SkyATP) enabled, if performing a CLI enrollment to SkyATP and the "Company Name" entered contains a space, the enrollment fails into an endless scrolling error message "Wrong Usage". This issue will cause enrollment in the SkyATP cloud to fail which might impact the SRX SkyATP function.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1738548DHCP offer is dropped at MX and specific EX platforms when an lt interface is used as the transport
Product-Group=junos
On MX and EX92_XX platforms, the DHCP offer will be dropped when LT interface is used to reach the DHCP server. DHCP relay will not work as expected due to this issue.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1670797Junos OS: MX Series: Gathering statistics in a scaled SCU/DCU configuration will lead to a device crash (CVE-2024-21603)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service. Please refer to https://supportportal.juniper.net/JSA75744 [juniper.net] for more information.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1737615MPC1 to MPC13E/LC2101, LC2103, LC480/T4000-FPC5/MPC based line card reboots when subscriber management services are configured
Product-Group=junos
When Junos EX, MX, SRX, T platforms with Modular Port Concentrators from MPC1 to MPC13E/LC2101, LC2103, LC480/T4000-FPC5/MPC based line cards are configured with subscriber management services with interface name that exceeds 19 characters, it leads to line card reboot causing service impact.
PR NumberSynopsisCategory: QFX RCB issues
1763588Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
PR NumberSynopsisCategory: Xellent Platform issues
1709817Ports with QSA adapter are down
Product-Group=junos
On Junos PTX1000 and PTX10002-60C/QFX10002-60C platforms, ports which use the QSA (QSFP-to-SFP Adapter) may not come up when running software version containing the fix for PR 1620527.
 
 

19.4R3-S13 - List of Known issues 

PR NumberSynopsisCategory: EX4300 PFE
1610408The pfex core might be seen after the device is running for a while
Product-Group=junosvae
In a Virtual chassis. the pfex core could be seen after the device is running for a while and due to PFE restart, VC may split and drop packets in forwarding plane. There is no specific time frame as well as any trigger.

Resolved In: junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.4R3 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: EX2300/3400 PFE
1742303DHCP packets traversing the switch even though the source mac is not present in accept-source-mac list
Product-Group=junos
In EX2300 & EX3400 devices, even though accept-source-mac knob is configured, DHCP Packets with the MAC address not present in the accept-source-mac list are accepted and traverse in the network.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4
PR NumberSynopsisCategory: SRX 5K SPC3 FPGAs
1671649Traffic loss may be seen due to SPC3's packets getting stuck
Product-Group=junos
On Junos MX960, MX480 and SRX5000 series platforms with SPC3 card, Flowd restart or PIC (Physical Interface Card) going offline/online may cause SPC3's sending of packets to get stuck.

Resolved In: evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R2-S1 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Fireall support for ACX
1737999Transit VPN traffic towards local CE failed in ARP resolution due to VRF lo0.x RE filter in place
Product-Group=junos
On ACX1K/2K platforms, when a lo0.x filter is configured under a vrf type routing-instance, any IPv4 transit traffic that makes ARP request to generate to the CE-facing interfaces will fail in ARP resolution due to the ARP request packets are discard by lo0.x filter if no specific term to accept the IPv4 packets

Resolved In: junos:21.2R3-S6
PR NumberSynopsisCategory: Border Gateway Protocol
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1681716The device goes down when an FRU has over-temperature
Product-Group=junos
On MX240, MX480, and MX960, when the temperature for a particular FRU is above the over-temperature condition, the chassisd will start the timer(240 secs). If the over-temperature condition persists after completing 240secs, the chassis will be shut down instead of bringing down the particular FRU. This will impact the whole device traffic.

Resolved In: evo:24.1R1-EVO junos:24.1R1
PR NumberSynopsisCategory: Chotu platform software
1774558"FI: Cell underflow at the state stage" and "FI: Reorder cell timeout" error is seen impacting forwarding traffic on all MX platforms
Product-Group=junos
On all MX platforms with MPC9E line card and Packet forwarding Engine (PFE) Application-Specific Integrated Circuits (ASIC) based fabric, if image upgrade is performed then FPC reports "Cell underflow at the state stage" and "reorder cell timeout" messages and live forwarding traffic will be dropped as due to some internal scenarios 200G idles are getting programmed instead of 400G on Switch Processor Mezzanine Board (SPMB).

Resolved In: junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: AF interface in Node Virtualization
1685129Junos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filters (CVE-2024-21597)
Product-Group=junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. Please refer to https://supportportal.juniper.net/JSA75738 [juniper.net] for more information.

Resolved In: evo:21.2R3-S7-EVO evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:19.1R3-S10 junos:19.3R3-S9 junos:20.4R3-S9 junos:21.2R3-S2-J15 junos:21.2R3-S3 junos:21.4R3-S5 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: EVPN control plane issues
1739686Evpn-vxlan comp nh is not installed in pfe after peer reboot
Product-Group=junos
Evpn-vxlan comp nh is not installed in pfe after reboot.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S6-EVO evo:22.1R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R3-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:20.4R3-S9 junos:21.3R3-S5 junos:21.4R3-S4-J17 junos:21.4R3-S6 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1751386Re-ARP is not sent before MAC entry expires in EVPN environment on Junos MX platforms
Product-Group=junos
On Junos MX240, MX304, MX480, MX960, MX2010, MX2020, MX10004, MX10008 platforms with MPC10/MPC11/LC9600 line cards, Re-Address Resolution Protocol (Re-ARP) is not sent before Media Access Control (MAC) entry expires. It causes a service impact in Ethernet Virtual Private Network- Virtual eXtensible Local-Area Network (EVPN-VxLAN) scenario with IRB (Integrated Routing and Bridging) and BD (Bridge Domain) configured.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:21.2R3-S7 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1724298PS interface remains up while LT or RLT interface is down
Product-Group=junos
On all Junos MX platforms , PS (Pseudowire Subscriber) interface remains up while LT (Logical Interface) or RLT (Redundant Logical Tunnel) interface is brought down by disabling PFE (Packet Forwarding Engine) which will cause traffic black-holing.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.

Resolved In: evo:21.4R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R3-EVO evo:22.4R1-S2-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:19.2R3-S6-J1 junos:19.2R3-S7 junos:20.4R3-S6-J6 junos:20.4R3-S7 junos:21.2R3-S7 junos:21.4R3-S5 junos:22.2R3-S2 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Security platform jweb support
1698386Junos OS: J-Web: Multiple Vulnerabilities in PHP software
Product-Group=junos
PHP software included with Junos OS J-Web has been updated from 7.4.30 to 8.2.0 to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA71653 [juniper.net] for more information.

Resolved In: evo:23.2R1-EVO evo:23.3R1-EVO junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Odin Timing software
1632761ACX710 running G.8275.2 stuck at PTP Acquiring state if the connection is through some timing unaware nodes
Product-Group=junos
On the ACX710 platform, in Precision Time Protocol (PTP) with G.8275.2 profile scenario where topology has some intermediate non-PTP aware nodes, the clock might be stuck in ACQUIRING state.

Resolved In: junos:21.2R2-S1 junos:21.2R3 junos:21.3R2 junos:21.4R2 junos:22.1R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1568757The image validation is not supported during upgrading from Pre 21.2 to 21.2 and onward
Product-Group=junos
When upgrading from releases before Junos OS Release 21.2 to Release 21.2 and onward, validation and upgrade might fail. The upgrade requires using the 'no-validate' option to complete successfully. https://kb.juniper.net/TSB18251 [juniper.net]

Resolved In:
PR NumberSynopsisCategory: DHCP related Issues
1711644QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging (CVE-2023-44191)
Product-Group=junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73155 [juniper.net] for more information.

Resolved In: junos:21.2R3-S5 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1667069Junos OS: QFX5000 series, EX2300, EX3400, EX4100, EX4400, and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN (CVE-2023-44203)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73169 [juniper.net] for more information.

Resolved In: junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S2 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1571417BFD sessions over VTEP might fail
Product-Group=junos
On QFX 5K platforms, running BFD (Bidirectional Forward Detection) over VTEP (Virtual Tunnel End Point) using IRB (Integrated Routing and Bridging) interface in distributed mode might fail, as BFD over VTEP in distributed mode is not handled in PFE (Packet Forwarding Engine) software.

Resolved In: junos:20.1R3-S1 junos:20.2R3-S2 junos:20.3R3-S1 junos:20.4R2-S2 junos:20.4R3 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1721936Junos OS: SRX Series: flowd will crash when "tcp-encap" is enabled and specific packets are received (CVE-2024-21606)
Product-Group=junos
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75747 [juniper.net] for more information.

Resolved In: junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: SRX branch platforms
1768050ARP resolution does not work if generated from the L3 Interface such as the IRB interface
Product-Group=junos
On SRX300 series platforms, ARP (Address Resolution Protocol) resolution does not work if it is generated internally from the L3 (Layer 3) interface such as the IRB (Integrated Routing and Bridging) interface. The routing protocol connections will not get established resulting in traffic impact.

Resolved In: junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: MX10003/MX204 Linux issues (including driver issues)
1753908Device crash and control plane traffic gets impacted on Junos platforms
Product-Group=junos
On all Junos platforms, due to a timing issue, when monitor traffic is enabled on loopback interface (for debug purpose), in the presence of local TCP (Transmission Control Protocol) packet flow, it is observed that the device crashes and traffic gets impacted.

Resolved In: junos:20.4R3-S10 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.

Resolved In: junos:18.4R3-S11-J2 junos:20.2R3-S4 junos:20.3R3-S4 junos:20.4R3-S3 junos:21.2R3-S3 junos:21.3R2-S1 junos:21.3R3 junos:21.4R2 junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1732283Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=junos
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/JSA73153 [juniper.net] for more information.

Resolved In: evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1

 

Modification History

First publication 2024-01-26