Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 21.4R3-S9 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 21.4R3-S9 is now available.

21.4R3-S9 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
PR NumberSynopsisCategory: SRX2000/50000 issue
1811765The vmcore process crashes on when XLP PIC is initiated
Product-Group=junos
Severity=Major
On SRX5400/SRX5600/SRX5800 platforms, if vmcore is initiated for XLP PIC ( Extreme Low Power Peripheral Interface Controller ), vmcore process crashes.
PR NumberSynopsisCategory: BBE state synchronization issues
1811787The process bbe-smgd crash will be observed in the Subscriber login/logout scenario
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1820001Multiple processes on both the REs are crashing
Product-Group=junos
Severity=Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1796530High CPU utilization due to BMP to be running with the longest and highest run count
Product-Group=junos
Severity=Major
In a rare situation, BMP might falls into a loop processing rib-in RM update messages but none of message being sent out. It can hog CPU for long time until the BMP station state is bounced. Since BMP task has low priority, it will yield CPU if there are other tasks jump in. So BMP will only hog CPU when system is idle and won't block other important tasks.
PR NumberSynopsisCategory: BBE Remote Access Server
1826901The authd process crash is seen when subscriber management is enabled
Product-Group=junos
Severity=Major
On all Junos MX platforms, the authd process would crash if it attempts to access the subscriber management database (SDB) while the SDB is undergoing re-initialization due to a problem. Due to this, new subscriber login will be affected possibly for few seconds.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1801284The RE switchover will not be triggered in case of clock failure on SCBE3-MX
Product-Group=junos
Severity=Major
On MX platforms with SCBE3-MX (MX240, MX480 and MX960) due to a hardware failure of the Control Board, the Routing Engine(RE) switchover might not happen. This will result in the 19.4Mhz clock failure and has potential risk for chassis wide traffic impact. In worst case all revenue ports will be impacted. If the RE switchover is done in a timely manner then the device will recover because FPCs will try using the 19.4Mhz clock from the new master.
PR NumberSynopsisCategory: Class of Service
1760817Change in the cosd behaviour due to the CoS interface specific wildcards
Product-Group=junos
Severity=Major
On all Junos platforms, applying the class-of-service (CoS) interface specific wildcards was leading to an inconsistent behaviour of the class-of-service daemon (cosd) at different times.
PR NumberSynopsisCategory: CFM
1536417FPC might core if CFM flap trap monitor feature in use
Product-Group=junos
Severity=Major
FPC generates core file when flap-trap-monitor is used and performance monitoring flap occurs.
PR NumberSynopsisCategory: OpenSSL and related subsystems
1815253Junos OS: Multiple vulnerabilities resolved in OpenSSL (CVE-2024-4741, CVE-2024-2511)
Product-Group=junos
Severity=Major
The OpenSSL project has published security advisories for multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88107 [juniper.net] for more information.
PR NumberSynopsisCategory: Device Configuration Daemon
1799112A dcd crash is observed when EX series switches managed by Mist
Product-Group=junos
Severity=Minor
When handling configurations for mid-scale multiD (combination of many feature configurations) setups with Mist onboarded is leading the corruption of the dcd database.
PR NumberSynopsisCategory: ACX LAG infrastructure
1789949The egress ports on ACX710 incorrectly tagging traffic expected to be untagged over CCC/VPLS interfaces
Product-Group=junos
Severity=Major
On Junos ACX710 platforms, untagged packets egressing out of CCC(Circuit Cross Connect)/VPLS(Virtual Private LAN Service) interfaces that perform no-op (No-Operation) at the egress port are incorrectly tagged impacting the traffic to CE (Customer Edge) device.
PR NumberSynopsisCategory: DNX Multicast
1799619Acx-arm-feb core may be triggered if IGMP snooping is enabled and IGMP Query is received on the same port as IGMP Join
Product-Group=junos
Severity=Major
On Junos ACX5448 and ACX710 platforms, if IGMP (Internet Group Management Protocol) snooping is enabled, arrival of IGMP Query packet on a port where IGMP Join packet was previously received may lead to an inconsistency in NHDB (Next-Hop Database) and eventually trigger a core dump of acx-arm-feb process.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734The LFM session flaps will be observed at random
Product-Group=junos
Severity=Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1811300MACSec does not work on some ports on MX platforms with MPC11E line card
Product-Group=junos
Severity=Major
On Junos MX2010/MX2020 platforms with MX2K-MPC11E line cards, and MACSec (IEEE 802.1AE standard) configured on line card ports. When the line card comes online for the first time, it is seen that ports are not being mapped correctly (port group value mismatch between picd and security) resulting in MACSec not working on some ports.
PR NumberSynopsisCategory: EX4400 PFE software
1795807Cos rewrite rules does not work properly when input/output-vlan-map swap are configured
Product-Group=junos
Severity=Major
On Junos EX4400 platforms enabled with CoS rewrite, if there is rewrite-rule applied to the input/output-vlan-map swap interface, the rewrite-rule of the logical interfaces does not work properly since the priority value for the queue is not updating. There is no traffic impact due to this, only CoS rewrite value is not updating.
PR NumberSynopsisCategory: EX POE
1814715When PDs(power devices) are connected to all the PoE (power over ethernet) ports with LLDP enabled, the last port is not powered up
Product-Group=junos
Severity=Major
On EX2300P and EX3400 platforms, when PDs are connected to all the PoE ports with LLDP enabled, the last port is not powered up.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1808040VRRP multicast packets coming from external hosts connected to the EVPN-VXLAN fabric might get duplicated on QFX10k platforms
Product-Group=junos
Severity=Major
On QFX10k platforms having Seamless EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) DCI (Data Center Interconnect) Stitching configured with L2 (Layer 2) Bridged Overlay design, VRRP (Virtual Router Redundancy Protocol) multicast traffic may be flooded to all RNVEs (Regular Network Virtualization Equipment) and Wan-VTEPs (Wide Area Network - Virtual Tunnel Endpoints), irrespective of DF (Designated Forwarder)/NDF (Non-Designated Forwarder) role. This may result in duplicates of VRRP multicast packets.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1792128Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
Severity=Major
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1808353Traffic drop is seen when "monitor traffic interface" command is issued for an interface on Junos SRX platforms
Product-Group=junosvae
Severity=Major
On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.
PR NumberSynopsisCategory: idp flow creation, deletion, notification, session mgr intfce
1826377Memory leak will be observed on all SRX platforms when IDP is configured
Product-Group=junos
Severity=Critical
On SRX platforms with IDP (Intrusion Detection and Prevention) enabled, while processing IDP traffic a memory leak can occur which would lead to regular flow processing being affected as memory depletes eventually. This issue affects the following Junos releases: 21.2R3-S8, 21.4R3-S7/8, 22.2R3-S3/4, 22.3R3-S3, 22.4R3-S2/3, 23.2R2, 23.2R2-S1 and 24.2R1. All other releases are not affected by this issue.
PR NumberSynopsisCategory: jdhcpd daemon
1818919jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization is done
Product-Group=junos
Severity=Major
DHCP ALQ (Active Leasequery) Sessions go down due to core dumps in jdhcpd (Juniper DHCP Daemon). These jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization happens after the TCP (Transmission Control Protocol) connection comes up.
1822178JUNOS_REG:EX4650-48Y:ZTPv6:Failed to reconnect to device as unable to load configuration to device via shelscript from ztp server
Product-Group=junos
Severity=Major
During ZTP, if shell script is used (for config download), it will not work on EX46* platforms However, if the baseline config is downloaded via regular way (as config file and not shell script), it will work.
PR NumberSynopsisCategory: Flow Module
1807505On SRX5000 series and SRX4600, the setting "apply-to-half-close-state" for TCP sessions is not taking effect.
Product-Group=junos
Severity=Major
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.
1820291Junos OS: SRX4600 and SRX5000 Series: Sequence of specific PIM packets causes a flowd crash (CVE-2024-47503)
Product-Group=junos
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated and logically adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88133 [juniper.net] for more information.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1821452Junos OS: SRX5000 Series: Receipt of a specific malformed packet will cause a flowd crash (CVE-2024-47504)
Product-Group=junos
Severity=Critical
An Improper Validation of Specific Type of Input vulnerability in the packet forwarding engine (PFE) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). Please refer to https://supportportal.juniper.net/JSA88134 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1817228IPsec VPN traffic disruption after a change of Authentication protocol is seen on platforms running kmd process
Product-Group=junos
Severity=Major
On all Junos platforms that run kmd process, IPsec VPN tunnels experience traffic disruption after a change of authentication protocol (ESP is change to AH or vice versa).
PR NumberSynopsisCategory: Platform infra to support jvision
1769294Junos OS: Due to a race condition AgentD process causes a memory corruption and FPC reset (CVE-2024-47494)
Product-Group=junos
Severity=Critical
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88121 [juniper.net] for more information.
PR NumberSynopsisCategory: Key Management Daemon
1781993Memory leak is observed on MX series platforms that run kmd process
Product-Group=junos
Severity=Major
On all MX series platforms that support MS-MPC/MS-MIC cards, memory leak is observed on kmd (Key Management Deamon) process when IPSec VPN is configured with DiffieHellman group24. The issue is not seen on platforms that support iked process. Memory leak causes incorrect outputs for CLI ipsec/ike show commands and over time kmd might crash when reach its maximum memory, creating a core-dump and resulting in ipsec/vpn going down.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1827641Even though installed the license to both Master and Backup, Alarm LED might be lit with yellow on Backup.
Product-Group=junos
Severity=Major
On VC (Virtual Chassis) setup and licensing infra, the licenses are installed on both Routig engine but Alarm LED might be Yellow on Backup role.
PR NumberSynopsisCategory: Express Paradise PFE Sflow
1803542PTX10008 - Recurring logs -ppcfpc-multi-svcs.elf: FDB :: Ipv4 route operation 2 failed. Rt_index 1801
Product-Group=junos
Severity=Major
Recurring logs -ppcfpc-multi-svcs.elf: FDB :: Ipv4 route operation 2 failed. Rt_index are seen in PTX10008 after upgrade
PR NumberSynopsisCategory: Protocol Independant Multicast
1709038Junos OS and Junos OS Evolved: Receipt of specific PIM packet causes rpd crash when PIM is configured along with MoFRR (CVE-2024-39558)
Product-Group=junos
Severity=Major
An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically adjacent, unauthenticated attacker sending specific PIM packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS), when PIM is configured with Multicast-only Fast Reroute (MoFRR). Continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83018 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX access control list
1823280EX / QFX : dfw ERROR is seen whenever collecting RSI
Product-Group=junos
Severity=Major
On EX and QFX5K series switch with egress filters configured in the system, you may observe dfw error whenever collecting RSI.
PR NumberSynopsisCategory: QFX L2 PFE
1821012L2PT is not able to pass Destination MAC 01:00:0c:cc:cc:cc(CDP/VTP/UDLD frames) when frame is TAGGED.
Product-Group=junos
Severity=Major
Support for CDP/VTP/UDLD tag frames with a Destination MAC of 01:00:0c:cc:cc:cc has been added for L2PT.
1824023Restricted Proxy ARP feature does not work as expected
Product-Group=junos
Severity=Major
On all Junos QFX5K and EX4K platforms supporting restricted 'proxy-arp' feature, when restricted 'proxy-arp' is enabled on IRB (Integrated Routing and Bridging) interface, hosts within the same subnet will not be able to reach each other.
1824750Rebooting one linecard or FPC will cause the virtual-chassis on the EX4K and QFX5K devices to forward traffic in backup RTG interface
Product-Group=junos
Severity=Major
On EX4K/QFX5K VC (Virtual Chassis) with RTG (Redundant Trunk Group) enabled, if one of the VC members is rebooted without any RTG member link, the VC will start sending the traffic in the backup link. Forwarding of traffic on the backup link which is not supposed to forward the traffic will lead to storm in the network.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1798684On Junos QFX5K, EX4100, EX4300, EX4400 and EX4650, Type 5 tunnel traffic loss observed when all IRB interfaces are deleted
Product-Group=junos
Severity=Minor
On all Junos QFX5K, EX4100, EX4300, EX4400 and EX4650 platforms with EVPN-VxLAN (Ethernet Virtual Private Network-Virtual Extensible LAN), deleting the all IRB (Integrated Routing and Bridging) interfaces while still having Type 5 tunnels installed results in Type 5 tunnel traffic loss when Type 5 tunnel MAC (Media Access Control ) is same as global/chassis IRB MAC.
1804628The dcpfe process will crash in an EVPN-VxLAN scenario due to stale entries in PFE
Product-Group=junos
Severity=Major
On Junos QFX5100, QFX5110, QFX5120, QFX5200, EX4100, EX4400, and EX4650 platforms, the dcpfe process crashes in an Ethernet VPN Virtual Extensible LAN (EVPN-VXLAN) scenario when the Virtual Tunnel End Point Next-Hop(VTEP) NH changes. The dcpfe process crash will generate core-dump causing traffic disruption.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1797511[JDI-RCT-EVPNVXLAN-L2Stitching]: DCPFE core observed on QFX10k while running profile baseline in 22.2R3-S3.18 image
Product-Group=junos
Severity=Critical
In very rare instances of a large config commit, on the QFX10002-36Q routers, the dcpfe can core due to watchdog timeout. After the core, the dcpfe respawns and the system functions normally without any manual intervention.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1799073Auto-channelization is showing inconsistent behaviour on QFX platforms when there is fault on the channels
Product-Group=junos
Severity=Major
On all QFX platforms, auto-channelization failure is seen due to faults on any channels of breakout channels, leading to link downtime and traffic disruption.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758868100G optics set to CAUI4 on Junos QFX5200-32C platforms
Product-Group=junos
Severity=Major
The Port interface is set wrong on 100G optics on QFX5200-32C platform.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1805427The rpd process crashes during rpd restart on Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1709741The rpd process crash on backup RE will be observed during configuration removal or restoration
Product-Group=junos
Severity=Major
The rpd process crash on backup RE will be observed during configuration removal or restoration.
PR NumberSynopsisCategory: RPM and TWAMP
1660514RPM route tracking configuration doesn't work on EX9200 Series
Product-Group=junos
Severity=Minor
On the Junos EX9200 series device, RPM (Realtime Performance Monitoring) route tracking does not work even though the configuration gets committed without errors and RPM route tracking CLIs (Command Line Interface) doesn't work. As a result, the route tracking configuration will not take effect, consequently, the intended route will not get tracked. The output of commands like 'show route rpm-tracking' throws an error.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1827806mspmand crash on clear/show services sessions" parallel in high scale on MX platforms
Product-Group=junos
Severity=Major
On Junos MX with MS-MPC/MS-MIC cards, when clear service sessions are executed from multiple windows (approx 5 terminals), the PIC reboots and eventually all the service traffic will be impacted.
PR NumberSynopsisCategory: Track usability related J-Web PR, like UI layout, workflow
1823264Unable to Define NAT Policy Address Names Containing Dots or Slashes in J-Web
Product-Group=junos
Severity=Major
On all SRX series platforms enabled with J-Web, NAT (Network Address Translation) policies cannot be edited/added using J-Web if the destination address name contains '.' dot or '/' slash.
PR NumberSynopsisCategory: SRX branch platforms
1819054The ~root/.ssh directory contents is deleted on every reboot
Product-Group=junos
Severity=Major
On all SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
1827123Root user does not get logged out from shell
Product-Group=junos
Severity=Major
On the SRX 3xx series the root user does not get logged out from the shell mode even though the session logout time is configured. There is no traffic impact because of this issue, however, this is unexpected behaviour and not seen on other platforms.
PR NumberSynopsisCategory: MX10003/MX204 Linux issues (including driver issues)
1753908Device crash and control plane traffic gets impacted on Junos platforms
Product-Group=junos
Severity=Major
On all Junos platforms, due to a timing issue, when monitor traffic is enabled on loopback interface (for debug purpose), in the presence of local TCP (Transmission Control Protocol) packet flow, it is observed that the device crashes and traffic gets impacted.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376The 1G interface might be down after upgradation on SRX4600 platform
Product-Group=junos
Severity=Major
On SRX4600 platform, upgrading from any earlier release to Junos 23.2R2 or later whether via ISSU (in-service software upgrade) or a standard upgrade process can cause the 1G interfaces to go down when the speed is changed from 10G to 1G. As a result, the port fails to activate properly at 1G, remaining down and unable to transmit any traffic.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1788669Traffic drop due to mac-validate failure on MX platforms
Product-Group=junos
Severity=Major
On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberSynopsisCategory: DDos Support on MX
1807538DDOS related Error messages can be seen on MX platforms
Product-Group=junos
Severity=Major
On certain Junos MX platforms with SCFD (Suspicious Control Flow Detection) enabled, error messages related to DDOS (Distributed Denial Of Service) protection can seen when traffic volume is high with varied flows. There is no service impact because of this issue.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Minor
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1818692Configuration commit fails due to mustd process crash
Product-Group=junos
Severity=Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1645119Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=junos
Severity=Critical
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/JSA82992 [juniper.net] for more information.
1784818The non-root user will not be able to copy files
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
PR NumberSynopsisCategory: Issues related to NETCONF
1800859Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
1819656In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberSynopsisCategory: web filterig issues
1806786UTM Web filtering does not work for HTTPS traffic sent from Google Chrome browser or MS Edge v124
Product-Group=junos
Severity=Major
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1734703Speed configuration mismatch causes the ukern core on Junos PTX10008 and PTX10016 platforms
Product-Group=junos
Severity=Major
On Junos PTX10008 and PTX10016 platforms, when the speed configuration on the interface is not matching with the speed of the optics present in the port, it causes memory corruption because of this FPC will crash and restart. Traffic loss till the FPC restarts after the ukern core.
PR NumberSynopsisCategory: VCCP related PRs for virtual-chassis in MX
1801522AE child links in back member is in detached state
Product-Group=junos
Severity=Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1822867After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved MX platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberSynopsisCategory: usf ams related issues
1804616NSD validation failure results into upgrade failure for Junos MX platforms
Product-Group=junos
Severity=Major
On Junos MX240, MX480, MX960 platforms, the Network Security Daemon (nsd) validation fails during upgrades.


Modification History

First publication 2024-10-11