Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
MX10003 running Junos FIPS software
Alert Description
Junos Software Service Release version 19.3R3-S9 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 19.3R3-S9 is now available.
19.3R3-S9 - List of Fixed issues
PR Number
Synopsis
Category: BBE interface related issues
1734564
Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75725
[juniper.net]
for more information.
PR Number
Synopsis
Category: Border Gateway Protocol
1711727
Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75735
[juniper.net]
for more information.
1742287
Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/
JSA75723
[juniper.net]
for more information.
PR Number
Synopsis
Category: Captive Portal
1736937
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
PR Number
Synopsis
Category: ACX IFL, IFF creation
1691004
The PFE process crashes on ACX5448
Product-Group=junos
On Junos ACX5448 platforms, the PFE (Packet Forwarding Engine) process will crash after continuous IFD (Interface Device) flaps. As a result, all traffic will be lost until the process recovers on its own.
PR Number
Synopsis
Category: AF interface in Node Virtualization
1685129
Junos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filters (CVE-2024-21597)
Product-Group=junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. Please refer to https://supportportal.juniper.net/
JSA75738
[juniper.net]
for more information.
PR Number
Synopsis
Category: Express PFE FW Features
1716398
Junos OS: PTX Series and QFX10000 Series: Received flow-routes which aren't installed as the hardware doesn't support them, lead to an FPC heap memory leak (CVE-2023-22392)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73530
[juniper.net]
for more information.
PR Number
Synopsis
Category: Adresses ALG issues found in JSF
1598017
ALG traffic might be dropped
Product-Group=junos
On SRX-Series devices, ALG traffic might be dropped when incoming packet contains "HTTP/" and "rn" characters in data or NAT slipstream packets.
PR Number
Synopsis
Category: Firewall Network Address Translation
1702811
Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75757
[juniper.net]
for more information.
PR Number
Synopsis
Category: Firewall Policy
1694960
Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash (CVE-2024-21594)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75733
[juniper.net]
for more information.
PR Number
Synopsis
Category: Security platform jweb support
1736942
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
1747984
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/
JSA75729
[juniper.net]
for more information.
1763260
Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information (CVE-2024-21619)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. Please refer to https://supportportal.juniper.net/
JSA76390
[juniper.net]
for more information.
PR Number
Synopsis
Category: Layer 2 Control Module
1763053
LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR Number
Synopsis
Category: PTX1000 platform
1653316
Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition (CVE-2024-21600)
Product-Group=junos
An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75741
[juniper.net]
for more information.
PR Number
Synopsis
Category: Issues related to PKI daemon
1694604
IPSEC tunnel is not getting established back after the execution of 'clear security ike sa'
Product-Group=junos
On Junos SRX platforms, the IPSEC (Internet Protocol Security) tunnels do not get established after the tunnels are deleted using the command 'clear security ike sa'.
PR Number
Synopsis
Category: SRX Argon module
1540979
SkyATP CLI enrollment fails with the error message "Wrong usage" if company name has a space
Product-Group=junos
On SRX platforms with Sky Advanced Threat Prevention (SkyATP) enabled, if performing a CLI enrollment to SkyATP and the "Company Name" entered contains a space, the enrollment fails into an endless scrolling error message "Wrong Usage". This issue will cause enrollment in the SkyATP cloud to fail which might impact the SRX SkyATP function.
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1738548
DHCP offer is dropped at MX and specific EX platforms when an lt interface is used as the transport
Product-Group=junos
On MX and EX92_XX platforms, the DHCP offer will be dropped when LT interface is used to reach the DHCP server. DHCP relay will not work as expected due to this issue.
PR Number
Synopsis
Category: QFX RCB issues
1763588
Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
19.3R3-S9 - List of Known issues
PR Number
Synopsis
Category: EX2300/3400 PFE
1742303
DHCP packets traversing the switch even though the source mac is not present in accept-source-mac list
Product-Group=junos
In EX2300 & EX3400 devices, even though accept-source-mac knob is configured, DHCP Packets with the MAC address not present in the accept-source-mac list are accepted and traverse in the network.
Resolved In:
junos:20.4R3-S9 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4
PR Number
Synopsis
Category: Border Gateway Protocol
1709837
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA72510
[juniper.net]
for more information.
Resolved In:
evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR Number
Synopsis
Category: EVO L2 Control Protocols Support
1692022
Junos OS and Junos OS Evolved: The l2cpd will crash when a malformed LLDP packet is received (CVE-2023-36849)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71660
[juniper.net]
for more information.
Resolved In:
evo:21.4R3-S2-EVO evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.3X80-D39-EVO evo:22.3X80-D40-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.4R3-S3 junos:22.1R3-S3 junos:22.2R2-S1 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR Number
Synopsis
Category: jdhcpd daemon
1706709
Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75730
[juniper.net]
for more information.
Resolved In:
junos:19.2R3-S8 junos:19.4R3-S13 junos:20.4R3-S9 junos:21.2R3-S6-J13 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR Number
Synopsis
Category: Security platform jweb support
1779376
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS (CVE-2024-21620)
Product-Group=junos
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Please refer to https://supportportal.juniper.net/
JSA76390
[juniper.net]
for more information.
Resolved In:
junos:19.4R3-S13 junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR Number
Synopsis
Category: Kernel socket data replication issues for protocols that use
1711656
Junos OS: BGP flap on NSR-enabled devices causes memory leak (CVE-2024-21617)
Product-Group=junos
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75758
[juniper.net]
for more information.
Resolved In:
junos:19.1R3-S11 junos:19.2R3-S8 junos:19.4R3-S13 junos:20.2R3-S8 junos:20.4R3-S7 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3-S2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR Number
Synopsis
Category: DHCP related Issues
1711644
QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging (CVE-2023-44191)
Product-Group=junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73155
[juniper.net]
for more information.
Resolved In:
junos:21.2R3-S5 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR Number
Synopsis
Category: QFX L2 PFE
1667069
Junos OS: QFX5000 series, EX2300, EX3400, EX4100, EX4400, and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN (CVE-2023-44203)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73169
[juniper.net]
for more information.
Resolved In:
junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S2 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR Number
Synopsis
Category: SRX Argon module
1597179
AAMW functions will be bypassed on HTTPs after AppID package upgrade
Product-Group=junos
AAMW functions will be bypassed on HTTPs after AppID package upgraded to version 3313 or later in release 21.2R1.
Resolved In:
junos:21.2R2 junos:21.3R1
PR Number
Synopsis
Category: Remote Access VPN issues on SRX
1721936
Junos OS: SRX Series: flowd will crash when "tcp-encap" is enabled and specific packets are received (CVE-2024-21606)
Product-Group=junos
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA75747
[juniper.net]
for more information.
Resolved In:
junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1668419
Junos OS: MX Series: An FPC crash is observed when CFM is enabled in a VPLS scenario and a specific LDP related command is run (CVE-2023-44193)
Product-Group=junos
An Improper Release of Memory Before Removing the Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, low-privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73157
[juniper.net]
for more information.
Resolved In:
evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.4R3-S12 junos:20.2R3-S7 junos:20.3X75-D46 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.1R3-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1
PR Number
Synopsis
Category: Express ZX PFE L3 Features
1732283
Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=junos
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/
JSA73153
[juniper.net]
for more information.
Resolved In:
evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1
Modification History
First publication 2024-02-01
19.3R3-S9: Software Release Notification for JUNOS FIPS Software for MX10003