Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

SRX345 SRX380 SRX1500 running FIPS

Alert Description

Junos Software Service Release version 20.2R3-S9 is now available for download from the Junos software download site for FIPS SRX345, SRX380, and SRX1500

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.2R3-S9 is now available.

20.2R3-S9 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1774634Junos OS: EX4300 Series: If a specific CLI command is issued PFE crashes will occur (CVE-2024-30384)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows a locally authenticated attacker with low privileges to cause a Denial-of-Service (Dos). Please refer to https://supportportal.juniper.net/JSA79186 [juniper.net] for more information.
1775558Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term (CVE-2024-30410)
Product-Group=junos
An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interface. The intended function is that the lo0 firewall filter takes precedence over the revenue interface (ex. ge-0/0/0) firewall filter. Please refer to https://supportportal.juniper.net/JSA79100 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX Gen-3 RE, leveraged from Point Success Mt.Rainier
1774760RE switchover observed in SRX5K platforms when ethernet switchports failure scenario on SCB
Product-Group=junos
On SRX5K platforms when all ethernet switch ports on Switch Control Board(SCB) fail, it triggers the Routing Engine (RE) switch over and RE0 is stuck in "Disabled" state. As RE0 is disabled and RE1 does have the functionality to coordinate chassis. No PIC will turn up which were failed and triggered the failover and traffic impact will be there for those particular ports and the complete service impact will be there if RE1 had any issue when RE0 is in disable state. RE0 did not recover by its own from the disabled state until manual reboot is done.
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1625579The flowd process lost heartbeat for 45 consecutive seconds without alarm raised
Product-Group=junos
On SRX5K platforms with SPC3 card used, if the flowd process lost heartbeat for 45 consecutive seconds, all FPCs might reboot. However, the device marks the flowd process as down without alarm raised, the failover does not happen right away. Traffic loss might be seen due to this issue. Fix raises alarm at earlier stage. If cluster, there will be sooner failover.
1692611SRX cluster may fail in a rare scenario when node status changes to disabled state without going through the ineligible state
Product-Group=junos
On SRX1500/SRX4100/4200/SRX4600/SRX5400/5600/5800 with chassis cluster configured, the RE(Routing-Engine) & PFE (Packet Forwarding Engine) connection may break, and the cluster may fail when the node status changes from primary/secondary state to disabled state without going through the ineligible state.
PR NumberSynopsisCategory: A15 specific issue
1738188Failover can be seen on SRX5K cluster with SPC2 cards while executing RSI
Product-Group=junos
On all SRX5000 series platforms with SPC2 cards configured in a chassis cluster, when RSI is being collected which has the command 'i2csc fpc' in the script, an interrupt storm generates a CB (Control Board) alarm which triggers a failover. Intermittent traffic disruption could be seen till the failover is complete.
PR NumberSynopsisCategory: a20a40 specific issue
1560562The show chassis errors command is not supported on SRX5000 Series devices with RE3 and SCB3 installed anymore.
Product-Group=junos
The "show chassis errors" command became not supported on SRX5000 with RE3 and SCB3 installed.
1563978The show chassis ethernet-switch errors command unexpectedly shows error counters for port 14 on the SRX5800 device.
Product-Group=junos
A display issue with "show chassis ethernet-switch errors" command, which unexpectedly shows error counters for port 14 on SRX5800. As part of the fix, the counters are removed now.
1645817Line cards fail to come online state when the device is powered on with multiple cards
Product-Group=junos
On SRX5k and MX240/MX480/MX960 platforms, when device is powered on with multiple line cards, power might not be sufficient and few line cards fail to come into online state.
1663839Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS are observed at commit
Product-Group=junos
Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS is observed at commit on SRX5K platforms. This is caused by unsupported chassis component connection on SRX5K platforms during commit checks. This syslog message is informational only for SRX5K, and was removed.
1775880A flowd crash is observed if CP receives the packets due to some hardware memory issue
Product-Group=junos
On SRX5K platforms with SPC3 and SPC2 cards, flowd crash will be observed if CP (Central Point) receives the packets due to some hardware memory issue either on IOC (I/O card) or SPC (Services Processing Card) which requires session lookup.
PR NumberSynopsisCategory: chassisd related issues for high-end SRX platforms
1570433Missing snmp operation state method for SRX5800/MX960 platform
Product-Group=junos
Missing snmp operation state method for PDM (Power Distribution Module) on SRX5800/MX960 platform.
PR NumberSynopsisCategory: COS for australia platform
1596172"show interfaces queue < interface>" command output not correctly displaying bps values for throughput higher than 4.25Gbps
Product-Group=junos
"show interfaces queue < interface>" command output not correctly displaying bps values for throughput higher than 4.25Gbps. This behaviour is only present for throughput higher than 4.25Gbps per interface output queue.
PR NumberSynopsisCategory: This GNATS category is required to track NG-IOC PRs for SBU
1688658The flow sessions traversing the IOC2 card would time out early when Express Path is enabled
Product-Group=junos
On SRX5K series devices with IOC2 line-cards installed, when running JUNOS 21.2R1 or later where Express Path is enabled by default, sessions traversing the IOC2 card would time out early, leading to a traffic loss and unpredictable flow behavior.
PR NumberSynopsisCategory: PFE issue for flowd on australia SPU
1727027The datapath-debug packet-dump feature is not capturing the transit traffic packets
Product-Group=junos
On SRX5000 platforms with IOC3 card (SRX5K-MPC3-100G10G and SRX5K-MPC3-40G10G), datapath-debug packet-dump will stop capturing the transit traffic packets when datapath-debug packet filters with packet-dump are targeting the traffic on the interface which is configured with firewall filters.
PR NumberSynopsisCategory: BBE interface related issues
1734564Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75725 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
PR NumberSynopsisCategory: Class of Service
1757003Junos OS: MX Series: In a scaled subscriber scenario if CoS information is gathered, the mgd processes get stuck (CVE-2024-21610)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS on MX Series allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75751 [juniper.net] for more information.
PR NumberSynopsisCategory: EVPN control plane issues
1740634Junos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crash (CVE-2024-30394)
Product-Group=junos
A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79094 [juniper.net] for more information.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1748500Traffic drop will be observed when Label MPLS traffic egressing out on the IRB interface as IPV4
Product-Group=junos
On QFX10K platforms, Label MPLS (Multiprotocol Label Switching) (labeled-unicast) traffic egressing out on IRB (Integrated routing and bridging) interface as IPV4 traffic can get dropped.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1570371BFD over IPv6 does not work through an IPSec tunnel
Product-Group=junos
On SRX4100/SRX4200 platforms, BFD over IPv6 does not work through an IPSec tunnel. BFD functionality is affected due to this issue.
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
1761668False SNMP traps for power supply unit failure generated on SRX4100 and SRX4200 platforms
Product-Group=junosvae
On SRX4100/SRX4200 platforms, false SNMP traps for power supply unit failure generated as instability with the transmission in the hardware.
PR NumberSynopsisCategory: BSDX Software installation issues
1639610The error is seen during the NON-ISSU upgrade from 15.1 to 18.2 and later releases
Product-Group=junos
In SRX5400, SRX5600, SRX5800 platform while performing NON-ISSU software upgrade from 15.1 to 18.1 and later releases error is seen.
PR NumberSynopsisCategory: track re issu control procedure bugs
1740744ISSU doesn't break if INDB crashes
Product-Group=junos
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.
PR NumberSynopsisCategory: jdhcpd daemon
1706709Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75730 [juniper.net] for more information.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1750148Junos OS: SRX5000 Series with SPC2: Processing of specific crafted packets when ALG is enabled causes a transit traffic Denial of Service (CVE-2024-30405)
Product-Group=junos
An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79105 [juniper.net] for more information.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1540654Both primary and secondary nodes in chassis cluster go into disabled state in HA link down scenario
Product-Group=junos
In case of single control link on (SRX5400, SX5600, SRX5800) chassis cluster setup, when HA control link goes down, both nodes go into disable state due to fabric link still UP.
1736498In SRX MNHA cluster setup the RSI takes long time to generate
Product-Group=junos
In SRX MNHA cluster setup the RSI takes long time to generate on the MNHA backup node. The RSI includes the command "show security flow session session-state warm" which will collect all the sessions in warm state on the MNHA backup node - this output can be extensive and RSI is being generated an extended period of time, in known instances this was 1-2 hours.
PR NumberSynopsisCategory: Firewall Network Address Translation
1702811Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75757 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Policy
1694960Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash (CVE-2024-21594)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75733 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1718199Junos OS: MX Series with SPC3, and SRX Series: If specific IPsec parameters are negotiated iked will crash due to a memory leak (CVE-2024-21609)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) in Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an administratively adjacent attacker which can successfully establish IPsec tunnels to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75750 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1747984Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/JSA75729 [juniper.net] for more information.
1763260Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information (CVE-2024-21619)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
1779376Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS (CVE-2024-21620)
Product-Group=junos
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 Control Module
1748720Junos OS and Junos OS Evolved: l2cpd crash upon receipt of a specific TLV (CVE-2024-30380)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS), which causes the l2cpd process to crash by sending a specific TLV. Please refer to https://supportportal.juniper.net/JSA79171 [juniper.net] for more information.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1670507Fabric Destination error and Fabric plane going in check state after changing the fabric redundancy mode
Product-Group=junos
On MX240/480/960 platforms, Fabric drops are observed when changing the fabric redundancy mode.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1724253A race condition in the virtFS which results the vmcore on the VM Host platforms is running with FreeBSD 11
Product-Group=junos
On all VM host platforms with FreeBSD11, when there are more than one thread trying to perform Input/Output(I/O) operations on a virtual filesystem( virtFS) mountpoint, threads become stuck and wait for the I/O completion for longer than 1800000 ticks, which causes a kernel panic.
PR NumberSynopsisCategory: TCP/UDP transport layer
1700438The TCP sessions for BGP are closed on the backup RE
Product-Group=junos
On all Junos Platforms, if the interface configuration is altered to switch from one routing instance to another it might result in the closing of BGP session on the Backup Routing Engine.
PR NumberSynopsisCategory: vpls on branch (jseries and srx) platforms
1712161SRX3xx series may stop responding to SNMP requests when a wireless mPIM is installed.
Product-Group=junos
SRX3xx series may stop responding to SNMP requests when a wireless mPIM is installed. The wireless card times out responses to system SNMP requests which may then lock up SNMPD. There is no workaround, but recovery is to restart snmpd.
PR NumberSynopsisCategory: Issues related to PKI daemon
1694604IPSEC tunnel is not getting established back after the execution of 'clear security ike sa'
Product-Group=junos
On Junos SRX platforms, the IPSEC (Internet Protocol Security) tunnels do not get established after the tunnels are deleted using the command 'clear security ike sa'.
1745288Junos OS: An invalid certificate causes a Denial of Service in the Internet Key Exchange (IKE) process (CVE-2024-30397)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79179 [juniper.net] for more information.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1729152The FPC crash or flap in protocols will be seen as soon as port-mirroring or firewall filters with syslog action is enabled
Product-Group=junos
On MX150 platform, when port-mirroring or firewall with syslog configuration is enabled, there will be a memory leak which will cause depletion of buffer memory which will lead to flap in the protocols or the (Flexible PIC Concentrators) FPC crash. This will impact the traffic.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1711783Junos OS: QFX5000 Series and EX Series: Specific malformed LACP packets will cause flaps (CVE-2024-30388)
Product-Group=junos
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79089 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to control plane security
1781732Junos OS and Junos OS Evolved: Impact of Terrapin SSH Attack (CVE-2023-48795)
Product-Group=junos
An Improper Validation of Integrity Check Value vulnerability in OpenSSH before 9.6 of Juniper Networks Junos OS and Junos OS Evolved allows a remote attacker to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka the Terrapin Attack. Please refer to https://supportportal.juniper.net/JSA76462 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX branch platforms
1580667[SRX] error message tcp_timer_keep:Local(0x81100001:60753) Foreign(0x8f100001:33010) is seen in messages log every 80 seconds
Product-Group=junos
On SRX series platform with Chassis Cluster, tcp_timer_keep:Local(0x81100001:60753) Foreign(0x8f100001:33010) is seen in messages log every 80 seconds.
1581554Traffic is dropped to/through VRRP virtual IP on SRX380
Product-Group=junos
On SRX380, when using Integrated routing and bridging (IRB) interface, Virtual Router Redundancy Protocol (VRRP) VIP (Virtual IP) is not responding to pings (with accept-data configured) and traffic is not routed through the configured VRRP VIP address
1611400VPLS interface fails to forward traffic on SRX platform
Product-Group=junos
On all Junos SRX platforms, VPLS(Virtual Private LAN Service) interface configured output filter with policer action may stop forwarding the traffic. The VPLS interface shows output bytes as 0, although the input packets and bytes are incremented.
1646943No system or chassis alarm will be seen when device booting from backup partition
Product-Group=junos
On Junos SRX branch platforms, when the device boots up from the backup partition, the alert message will not be notified in "show system alarm". This issue has been seen from Junos 19.4R2 release.
1658968The DNS information is getting lost when IPCP flaps
Product-Group=junos
On all SRX-branch series platforms working as a PPPoE (Point-to-Point Protocol over Ethernet) client and a DHCP (Dynamic Host Configuration Protocol) server, DNS (Domain Name System) information is getting lost, for which the DHCP client won't receive DHCP information and DNS packets will not get resolved to result in the packet drops. This issue happens when the IPCP (Internet Protocol Control Protocol) source address is not getting copied and IPCP is getting flapped due to the interface (DHCP interface) being flapped.
1661816fxp0 works under disable state in SRX300
Product-Group=junos
SRX300 runs in HA mode, fxp0 could be unexpectedly UP even though "disable" is configured.
1706933Junos OS: SRX 300 Series: Specific link local traffic causes a control plane overload (CVE-2024-21605)
Product-Group=junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75746 [juniper.net] for more information.
1715247Interface speed stays 100Mbps when removing speed and duplex command separately
Product-Group=junos
On SRX branch series, when the interface speed is set to 100Mbps and the link-mode is set to full-duplex, the interface speed remains at 100Mbps even the speed and duplex commands are removed separately.
1719108OAM not working with flexible-vlan-tagging
Product-Group=junos
OAM is not working when flexible-vlan-tagging is enabled
1738271"Minor Autorecovery information needs to be saved" alarm is not displayed after zeroize
Product-Group=junos
On SRX Branch platform, "Minor Autorecovery information needs to be saved" alarm is not displayed after running zeroize command
1739520Random physical interfaces doesn't come up after a reboot
Product-Group=junos
On SRX345, some interface ports couldn't able to get correct medium (FIBRE or COPPER) sometimes after multiple reboot due to that SFP optics inserted may not come up after a reboot.
1744108Commit panic reboot observed after implementing system processes watchdog timeout 180 on SRX hardware platforms
Product-Group=junos
On SRX hardware platforms, configuring set system processes watchdog related command causes commit panic reboot. Watchdog related commands are unsupported on SRX hardware platforms.
1746202Kernel CPU temperature becomes high and the flowd process crashes with dual VLAN tag configured
Product-Group=junos
On all SR3xx platforms having Q-in-Q tunnelling on VPLS (Virtual Private Local Area Network Service) over GRE (Generic Routing Encapsulation) tunnel, it is seen that due to dual VLAN (Virtual Local Area Network) tag configuration, the kernel CPU (Central Processing Unit) temperature becomes high along with the flowd process getting crashed.
1770303Inter and intra VLAN traffic drop can be seen on the SRX branch series
Product-Group=junos
On all Junos SRX branch series devices, intra and inter-VLAN (Virtual Local Area Network) traffic drop will be seen when the devices are running in ethernet-switching mode and STP(Spanning Tree Protocol) is configured on the respective interface for the VLANs.
PR NumberSynopsisCategory: SRX5XX platform
16209828-Port Gigabit Ethernet SFP XPIM not passing traffic after software upgrade
Product-Group=junos
On SRX550 platform, after doing a software upgrade, 8-Port Gigabit Ethernet SFP XPIM is not passing traffic
1634965[SRX] SRX550HM interfaces LED of ge-0/0/6-9 will auto turn off after device bootup some minutes
Product-Group=junos
SRX550HM interfaces LED of ge-0/0/6-9 will auto turn off after device bootup some minutes.
PR NumberSynopsisCategory: SRX-1RU platfom chassisd SW defects
1711467SRX4600 doesn't support ae interfaces
Product-Group=junos
On Junos SRX4600 platforms, ae interfaces doesn't come up or not work properly when configured in HA (High Availability) cluster mode.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1566065CLI-command "show pfe statistics traffic" shows wrong output
Product-Group=junos
cli-command "show pfe statistics traffic" shows wrong output and will be disabled in future JunOS releases as the correct place to check these statistics on SRX is PFE/flow-based "show pfe statistic" command
1654838The control link may not come up during the reboot
Product-Group=junos
On SRX4600 platforms, during reboot when the port signal is unstable, it may cause a control link down.
1748971SRX4600 misleading Fan speed syslog output after removing or inserting one Fan tray unit
Product-Group=junos
On SRX4600, misleading Fan speed syslog is generated after removing or inserting one Fan tray unit.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1590099The ISSU might abort due to unsuccessful image validation on all SRX platforms
Product-Group=junos
On all SRX platforms, the image validation will fail when ISSU from an image earlier than 21.2R1 (with stable11 freebsd) to an image later than 21.2R1 (with stable12 freebsd) which will cause the ISSU will abort. This is due to incompatible BSD releases. This PR has enabled the no-validate option so that this validation can be skipped for future releases.
PR NumberSynopsisCategory: Issues related to NETCONF
1702241Junos OS and Junos OS Evolved: A low-privileged user can access confidential information (CVE-2024-21615)
Product-Group=junos
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system. Please refer to https://supportportal.juniper.net/JSA75756 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX RCB issues
1763588Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
PR NumberSynopsisCategory: Windsurf interfaces software
1793999The 'no-flow-control' interface configuration not retained post ISSU on MX platforms
Product-Group=junos
Flow-control pause frames will be sent out of the interface even with the knob 'no-flow-control' enabled on Junos MX platforms after the ISSU upgrade. This issue will not be seen with non-ISSU software upgrades.
 
 

20.2R3-S9 - List of Known issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1698624cRPD: Multiple vulnerabilities resolved in 23.4R1 release
Product-Group=junos
Multiple vulnerabilities have been resolved in Juniper Networks Junos cRPD by updating third party software included with cRPD. Please refer to https://supportportal.juniper.net/JSA79107 [juniper.net] for more information.

Resolved In: junos:20.3X75-D43 junos:22.4R1-S1 junos:22.4R1-S2 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: PR category for Talus FPGA
1706756TX would be stuck and no packet can be transferred by the SPC3 card
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 platforms, TX(transmit) would be stuck and no packet can be transferred by the SPC3 card.

Resolved In: junos:20.4R3-S6 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1641793Traffic might be dropped due to the RX queue being full
Product-Group=junos
Incoming packets might be sent to RX queues of core0 or core14 mistakenly, might result in the queue buffer full and the packets getting dropped.

Resolved In: junos:19.4R3-S9 junos:20.3R3-S5 junos:20.4R3-S10 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.2R3-S7 junos:21.3R3 junos:21.4R2 junos:21.4R3 junos:21.4R3-S6 junos:22.1R2 junos:22.1R3-S5 junos:22.2R1 junos:22.2R2 junos:22.3R1
PR NumberSynopsisCategory: SRX 5K SPC3 FPGAs
1671649Traffic loss may be seen due to SPC3's packets getting stuck
Product-Group=junosvae
On Junos MX960, MX480 and SRX5000 series platforms with SPC3 card, Flowd restart or PIC (Physical Interface Card) going offline/online may cause SPC3's sending of packets to get stuck.

Resolved In: evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R2-S1 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1750441Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-30395)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79095 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: AF interface in Node Virtualization
1685129Junos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filters (CVE-2024-21597)
Product-Group=junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. Please refer to https://supportportal.juniper.net/JSA75738 [juniper.net] for more information.

Resolved In: evo:21.2R3-S7-EVO evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:19.1R3-S10 junos:19.3R3-S9 junos:20.4R3-S9 junos:21.2R3-S2-J15 junos:21.2R3-S3 junos:21.4R3-S5 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Express PFE L3 Multicast
1774562PIM join are not learnt for multicast IPs
Product-Group=junos
On Junos PTX platforms, with PIM BIDR (Protocol Independent Multicast- Bidirectional) mode with "set protocols pim rp bidirectional address <> group-ranges <>" configuration, PIM/MLD joins will not be learnt for multicast IPs other than link local IP and MY IP which will lead to traffic impact. Also, lo0 filter which were introduced with PR 1701756 for IGMP and MLD will be applied only for MY IPs and Link local IPs. For any other IPs other than above, lo0 filter will not work.

Resolved In: junos:20.3X75-D440 junos:22.4R3-S2
PR NumberSynopsisCategory: SRX1500 platform software
1521666Hide routing-instance under edit system name-server for SRX Series devices starts from Junos OS Release 20.4.
Product-Group=junos
Start from 20.4 releases, "routing-instance" under "edit system name-server" will be hiden in CLI configuration mode for SRX platform. The target platforms for this feature are MX, QFX and PTX.

Resolved In: junos:20.4R1
1729671When there is a power outage happens after the first upgrade, the reboot device gets stuck at volume booting
Product-Group=junosvae
SRX1500 devices get stuck at volume booting after an upgrade and reboot, followed by a power outage. The device is stuck in this state and continues to boot.

Resolved In: junos:21.4R3-S6 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.2R3-S3 junos:22.3R3 junos:22.3R3-S3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1632586Annotate ip command might bring IP monitoring down and both nodes in MNHA (Multinode high-availability) mode goes into INELIGIBLE state
Product-Group=junos
On SRX5k series platforms with MNHA mode, if "monitor ip" is configured under routing-instance and when try to add annotate ip command both devices might move into INELIGIBLE state and complete traffic may drop during the issue.

Resolved In: junos:20.4R3-S3 junos:21.1R3 junos:21.2R3 junos:21.3R2
PR NumberSynopsisCategory: interfaces and zones for junos js software
1711729The 'targeted-broadcast' feature will not work on some SRX platforms.
Product-Group=junos
On SRX 1500, SRX4100, SRX4200 and SRX4600 based platforms running Junos, 'targeted-broadcast' feature will not work. As a result, features like wake-on LAN (WOL) which rely on targeted broadcast will be affected.

Resolved In: junos:20.4R3-S7 junos:21.4R3-S3 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1669322Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS).

Resolved In: junos:19.3R3-S2-J1 junos:19.4R3-S9 junos:20.3R3-S5 junos:20.3X75-D35 junos:20.3X75-D42 junos:21.2R3-S1 junos:21.2R3-S2 junos:21.2X32-D10 junos:21.3R3-S1 junos:21.4R3 junos:22.1R2 junos:22.1R3 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
1678431Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash (CVE-2024-21613)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75754 [juniper.net] for more information.

Resolved In: evo:22.2R2-EVO junos:19.4R3-S13 junos:20.3X75-D35 junos:20.3X75-D42 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S3 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1640813Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured (CVE-2024-30382)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79174 [juniper.net] for more information.

Resolved In: junos:19.3R3-S9 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.3R3 junos:21.4R3 junos:22.1R2 junos:22.2R1
PR NumberSynopsisCategory: all ipv6 dhcp bugs on srx platforms
1770332DHCP server not responding to some clients
Product-Group=junos
SRX DHCP server does not respond to some clients after upgrading to 21.4R3-S5.

Resolved In: junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: SRX branch platforms
1768050ARP resolution does not work if generated from the L3 Interface such as the IRB interface
Product-Group=junos
On SRX300 series platforms, ARP (Address Resolution Protocol) resolution does not work if it is generated internally from the L3 (Layer 3) interface such as the IRB (Integrated Routing and Bridging) interface. The routing protocol connections will not get established resulting in traffic impact.

Resolved In: junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1746567Junos OS: SRX4600 Series: A high amount of specific traffic causes packet drops and an eventual PFE crash (CVE-2024-30398)
Product-Group=junosvae
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79176 [juniper.net] for more information.

Resolved In: junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1683213SRX4600HA might not failover properly due to a hardware failure
Product-Group=junosvae
In SRX4600 platform, there is a possibility of raising alarm function might not work in FPGA failure. It might affect device availability.

Resolved In: junos:20.4R3-S10 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1750634Traffic transfer/receive is impacted for SPC3 CPU cores connected to the affected PCIe bus when the SPC3 card boots up
Product-Group=junos
On MX and SRX platforms with SPC3 card, SPC3 (Services Processing Card 3) CPU cores connected to the affected PCIe (Peripheral Component Interconnect) bus (7 CPU cores) getting into a bad state will not transfer any traffic i.e. traffic loss during SPC3 card bootup due to incorrect register settings.

Resolved In: evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.4R3-S9 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Unified Services Framework
1618913Traffic might be dropped due to the TX queue memory leak on PCI interface
Product-Group=junos
On platforms with SPC3 services card, due to flowd daemon crash, it might trigger flowd re-start due to which FPGA (field programmable gate array) DMA module might be stuck.

Resolved In: evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:19.4R3-S8 junos:21.2R3-S1 junos:21.3R3 junos:21.4R2 junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1
1664517SPC3: Receive [Rx] queue of direct memory access might be stuck which may cause issues in packet processing
Product-Group=junos
SPC3:Receive [Rx] queue of direct memory access might be stuck which may cause issues in packet processing

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R2-S2 junos:22.1R3 junos:22.1R3-S5 junos:22.2R2 junos:22.2R3 junos:22.2R3-S4 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1

Modification History

First publication 2024-05-14