Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX10003 running Junos FIPS software

Alert Description

Junos Software Service Release version 19.3R3-S9 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.3R3-S9 is now available.

19.3R3-S9 - List of Fixed issues 

PR NumberSynopsisCategory: BBE interface related issues
1734564Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75725 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: ACX IFL, IFF creation
1691004The PFE process crashes on ACX5448
Product-Group=junos
On Junos ACX5448 platforms, the PFE (Packet Forwarding Engine) process will crash after continuous IFD (Interface Device) flaps. As a result, all traffic will be lost until the process recovers on its own.
PR NumberSynopsisCategory: AF interface in Node Virtualization
1685129Junos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filters (CVE-2024-21597)
Product-Group=junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. Please refer to https://supportportal.juniper.net/JSA75738 [juniper.net] for more information.
PR NumberSynopsisCategory: Express PFE FW Features
1716398Junos OS: PTX Series and QFX10000 Series: Received flow-routes which aren't installed as the hardware doesn't support them, lead to an FPC heap memory leak (CVE-2023-22392)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73530 [juniper.net] for more information.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1598017ALG traffic might be dropped
Product-Group=junos
On SRX-Series devices, ALG traffic might be dropped when incoming packet contains "HTTP/" and "rn" characters in data or NAT slipstream packets.
PR NumberSynopsisCategory: Firewall Network Address Translation
1702811Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75757 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Policy
1694960Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash (CVE-2024-21594)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75733 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1747984Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/JSA75729 [juniper.net] for more information.
1763260Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information (CVE-2024-21619)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 Control Module
1763053LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: PTX1000 platform
1653316Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition (CVE-2024-21600)
Product-Group=junos
An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75741 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to PKI daemon
1694604IPSEC tunnel is not getting established back after the execution of 'clear security ike sa'
Product-Group=junos
On Junos SRX platforms, the IPSEC (Internet Protocol Security) tunnels do not get established after the tunnels are deleted using the command 'clear security ike sa'.
PR NumberSynopsisCategory: SRX Argon module
1540979SkyATP CLI enrollment fails with the error message "Wrong usage" if company name has a space
Product-Group=junos
On SRX platforms with Sky Advanced Threat Prevention (SkyATP) enabled, if performing a CLI enrollment to SkyATP and the "Company Name" entered contains a space, the enrollment fails into an endless scrolling error message "Wrong Usage". This issue will cause enrollment in the SkyATP cloud to fail which might impact the SRX SkyATP function.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1738548DHCP offer is dropped at MX and specific EX platforms when an lt interface is used as the transport
Product-Group=junos
On MX and EX92_XX platforms, the DHCP offer will be dropped when LT interface is used to reach the DHCP server. DHCP relay will not work as expected due to this issue.
PR NumberSynopsisCategory: QFX RCB issues
1763588Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
 
 

19.3R3-S9 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1742303DHCP packets traversing the switch even though the source mac is not present in accept-source-mac list
Product-Group=junos
In EX2300 & EX3400 devices, even though accept-source-mac knob is configured, DHCP Packets with the MAC address not present in the accept-source-mac list are accepted and traverse in the network.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4
PR NumberSynopsisCategory: Border Gateway Protocol
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: EVO L2 Control Protocols Support
1692022Junos OS and Junos OS Evolved: The l2cpd will crash when a malformed LLDP packet is received (CVE-2023-36849)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71660 [juniper.net] for more information.

Resolved In: evo:21.4R3-S2-EVO evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.3X80-D39-EVO evo:22.3X80-D40-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.4R3-S3 junos:22.1R3-S3 junos:22.2R2-S1 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: jdhcpd daemon
1706709Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75730 [juniper.net] for more information.

Resolved In: junos:19.2R3-S8 junos:19.4R3-S13 junos:20.4R3-S9 junos:21.2R3-S6-J13 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Security platform jweb support
1779376Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS (CVE-2024-21620)
Product-Group=junos
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.

Resolved In: junos:19.4R3-S13 junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Kernel socket data replication issues for protocols that use
1711656Junos OS: BGP flap on NSR-enabled devices causes memory leak (CVE-2024-21617)
Product-Group=junos
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75758 [juniper.net] for more information.

Resolved In: junos:19.1R3-S11 junos:19.2R3-S8 junos:19.4R3-S13 junos:20.2R3-S8 junos:20.4R3-S7 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3-S2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: DHCP related Issues
1711644QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging (CVE-2023-44191)
Product-Group=junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73155 [juniper.net] for more information.

Resolved In: junos:21.2R3-S5 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1667069Junos OS: QFX5000 series, EX2300, EX3400, EX4100, EX4400, and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN (CVE-2023-44203)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73169 [juniper.net] for more information.

Resolved In: junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S2 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: SRX Argon module
1597179AAMW functions will be bypassed on HTTPs after AppID package upgrade
Product-Group=junos
AAMW functions will be bypassed on HTTPs after AppID package upgraded to version 3313 or later in release 21.2R1.

Resolved In: junos:21.2R2 junos:21.3R1
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1721936Junos OS: SRX Series: flowd will crash when "tcp-encap" is enabled and specific packets are received (CVE-2024-21606)
Product-Group=junos
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75747 [juniper.net] for more information.

Resolved In: junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1668419Junos OS: MX Series: An FPC crash is observed when CFM is enabled in a VPLS scenario and a specific LDP related command is run (CVE-2023-44193)
Product-Group=junos
An Improper Release of Memory Before Removing the Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, low-privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73157 [juniper.net] for more information.

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.4R3-S12 junos:20.2R3-S7 junos:20.3X75-D46 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.1R3-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1732283Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=junos
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/JSA73153 [juniper.net] for more information.

Resolved In: evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1

 

Modification History

First publication 2024-02-01