Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

SRX345 SRX380 and SRX1500 running Junos FIPS software

Alert Description

Junos Software Service Release version 20.2R3-S10 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 20.2R3-S10 is now available.

20.2R3-S10 - List of Fixed issues 

PR NumberSynopsisCategory: Border Gateway Protocol
1709837
Critical
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
Severity=Critical
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.
1755287
Major
Junos OS and Junos OS Evolved: Malformed BGP UPDATE causes rpd crash (CVE-2024-39552)
Product-Group=junos
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the rpd process to crash leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75726 [juniper.net] for more information.
PR NumberSynopsisCategory: dns-proxy feature
1688481
Major
The chassis cluster will not respond to DNS queries when configured with DNS proxy service
Product-Group=junos
Severity=Major
On Junos SRX platforms with an operational DNS (Domain Name System) server, the chassis cluster will not respond to DNS queries when configured with DNS proxy service.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734
Major
The LFM session flaps will be observed at random
Product-Group=junos
Severity=Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1814404
Major
Junos OS: SRX1500, SRX4100, SRX4200: Execution of low-privileged CLI command results in chassisd crash (CVE-2025-21596)
Product-Group=junos
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' command to cause the chassis daemon (chassisd) to crash and restart, resulting in a temporary Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA92864 [juniper.net] for more information.
PR NumberSynopsisCategory: track re issu control procedure bugs
1740744
Major
ISSU doesn't break if INDB crashes
Product-Group=junos
Severity=Major
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.
PR NumberSynopsisCategory: Flow Module
1820291
Critical
Junos OS: SRX4600 and SRX5000 Series: Sequence of specific PIM packets causes a flowd crash (CVE-2024-47503)
Product-Group=junos
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88133 [juniper.net] for more information.
PR NumberSynopsisCategory: User Firewall related issues
1805233
Critical
Junos OS: Multiple vulnerabilities in OSS component nginx resolved
Product-Group=junos
Severity=Critical
Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes. Please refer to https://supportportal.juniper.net/JSA88135 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1834204
Major
SRX becomes unresponsive when SNMP requests are sent via the fxp0 interface immediately after a reboot
Product-Group=junos
Severity=Major
On all SRX platforms (except SRX1600, SRX2300, SRX4700 and SRX5000 series with SPC3 card) using the IPsec-key-management service (KMD) for VPNs (Virtual private networks), the SRX becomes almost unresponsive impacting network when SNMP (Simple Network Management Protocol) requests for VPN information arrives from the PFE and are sent via the fxp0 interface immediately after a reboot before the IPC ( Interprocess communication) connection to the PFE is established.
PR NumberSynopsisCategory: Platform infra to support jvision
1769294
Critical
Junos OS: Due to a race condition AgentD process causes a memory corruption and FPC reset (CVE-2024-47494)
Product-Group=junos
Severity=Critical
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88121 [juniper.net] for more information.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1695867
Major
VMHOST based platforms rebooted unexpectedly due to corruption in the system
Product-Group=junos
Severity=Major
On all Junos platforms with VMHOST, the device rebooted unexpectedly due to a minor corruption in the system.
1838460
Minor
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Minor
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: RPD API infrastructure
1765417
Major
Junos OS and Junos OS Evolved: cRPD: Receipt of crafted TCP traffic can trigger high CPU utilization(CVE-2024-39547)
Product-Group=junos
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU-based Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88108 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
Severity=Major
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).
PR NumberSynopsisCategory: SRX Argon module
1661766
Major
Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash (CVE-2024-47506)
Product-Group=junos
Severity=Major
A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88137 [juniper.net] for more information.
1801893
Critical
Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system (CVE-2025-21592)
Product-Group=junos
Severity=Critical
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the file system. Please refer to https://supportportal.juniper.net/JSA92860 [juniper.net] for more information.
1815751
Critical
Junos OS: SRX Series: Low privileged user able to access sensitive information on file system (CVE-2024-39527)
Product-Group=junos
Severity=Critical
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system. Please refer to https://supportportal.juniper.net/JSA88104 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX branch platforms
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1747009
Major
Traffic from subscribers will be dropped by Junos based MX platforms
Product-Group=junos
Severity=Major
On Junos based MX platforms in enhanced subscriber management scenario, with 'routing-services' and 'rpf-check' feature enabled all traffic from subscribers will be dropped.
1788669
Major
Traffic drop due to mac-validate failure on MX platforms
Product-Group=junos
Severity=Major
On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberSynopsisCategory: Trio pfe qos software
1770750
Critical
Junos OS: MX Series: Trio-based FPCs: Continuous IFD flaps causes local FPC to crash (CVE-2024-47493)
Product-Group=junos
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series platforms with Trio-based FPCs allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88119 [juniper.net] for more information.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1784593
Major
Junos OS: MX Series: The PFE will crash on running specific command (CVE-2024-47496)
Product-Group=junos
Severity=Major
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88123 [juniper.net] for more information.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1784818
Major
The non-root user will not be able to copy files
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.
PR NumberSynopsisCategory: usf service set related issues
1779424
Major
Junos OS: MX Series with SPC3 line card: Port flaps causes rtlogd memory leak leading to Denial of Service (CVE-2024-39550)
Product-Group=junos
Severity=Major
A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events cause ( which can be done by repeated port flaps) to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83012 [juniper.net] for more information.

 


 

20.2R3-S10 - List of Known issues 

PR NumberSynopsisCategory: SRX DNS DGA and tunneling related
1755484
Major
Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash (CVE-2024-39529)
Product-Group=junos
A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82988 [juniper.net] for more information.

Resolved In: junos:21.4R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Border Gateway Protocol
1708088
Major
Junos OS and Junos OS Evolved: BGP update message containing aggregator attribute with an ASN value of zero (0) is accepted (CVE-2024-47507)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices. Please refer to https://supportportal.juniper.net/JSA88138 [juniper.net] for more information.

Resolved In: evo:21.4R3-S7-EVO evo:22.2R3-S4-EVO evo:22.2X100-D20-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S10 junos:19.4R3-S14 junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-S7-J20 junos:21.2R3-S7-J26 junos:21.2R3-S8 junos:21.4R3-S6 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S4 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1 junos:24.2R2
1744801
Critical
Junos OS and Junos OS Evolved: BGP multipath incremental calculation is resulting in an rpd crash (CVE-2024-39554)
Product-Group=junos
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash and restart, resulting in a Denial of Service (DoS). Since this is a timing issue (race condition), the successful exploitation of this vulnerability is outside the attacker's control. However, continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83014 [juniper.net] for more information.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.2R2
1750441
Major
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-30395)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79095 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S4-J27 junos:21.2R3-S4-J30 junos:21.2R3-S4-J37 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.2R2
1787290
Critical
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
1797147
Major
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP path attribute leads to an RPD crash (CVE-2024-47491)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88116 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S7-J26 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S3-J17 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1 junos:24.3R2
1807533
Critical
Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash (CVE-2024-39525)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88102 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S8 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1814083
Critical
Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39515)
Product-Group=junos
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1815222
Critical
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39516)
Product-Group=junos
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled. Please refer to https://supportportal.juniper.net/JSA88100 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1821241
Critical
Junos OS and Junos OS Evolved: When BGP traceoptions are configured, receipt of malformed BGP packets causes RPD to crash (CVE-2025-21598)
Product-Group=junos
An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue requires a BGP session to be established. This issue can propagate and multiply through multiple ASes until reaching vulnerable devices. Please refer to https://supportportal.juniper.net/JSA92867 [juniper.net] for more information.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.4R3-S5-EVO evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:23.4X100-D11-EVO evo:23.4X100-D20-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:21.2R3-S8-J13 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1-S1 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
1823612
Major
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2025-21600)
Product-Group=junos
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.. Please refer to https://supportportal.juniper.net/JSA92870 [juniper.net] for more information.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S2-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: ChassisD changes specific for DNX series.
1708557
Critical
Junos OS: Attempting to access specific sensors on platforms not supporting these will lead to a chassisd crash (CVE-2024-39530)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82989 [juniper.net] for more information.

Resolved In: junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1840734
Major
RLT ifl remains down after RLT unit interface configuration is modified
Product-Group=junos
On all Junos platforms which support PS over RLT, after modifying or deleting and re-adding a logical interface on RLT interface, the logical interface remains down and the following log messages is seen in the messages log:DCD_CONFIG_WRITE_FAILED: IFL rlt0.0 configuration write failed for an IFL ADD: File exists after configuration change.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:21.2R3-S9 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Security platform jweb support
1725808
Critical
Junos OS: J-Web: Multiple vulnerabilities resolved in PHP software (CVE-2023-0567, CVE-2023-0662, CVE-2023-3823, CVE-2023-3824, CVE-2023-0568)
Product-Group=junos
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88120 [juniper.net] for more information.

Resolved In: evo:23.3R2-EVO junos:21.4A3 junos:21.4R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R1-S2 junos:23.2R2 junos:23.2R2-S2 junos:23.3R2 junos:23.4R1 junos:23.4R1-S2 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1631607
Minor
IPv6 host route resolutions disappear from 'forwarding-table' after a ping test
Product-Group=junos
IPv6 route resolutions for IPv6 hosts is missing from the 'route forwarding-table' after pinging hosts within the ip prefix.

Resolved In: junos:18.4R3-S11 junos:21.2R3 junos:21.3R3 junos:21.4R2 junos:22.1R1 junos:22.2R1
PR NumberSynopsisCategory: SRX branch platforms
1777464
Critical
Junos OS: Multiple vulnerabilities in OSS component nginx resolved (CVE-2023-44487)
Product-Group=junos
Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes. Please refer to https://supportportal.juniper.net/JSA88135 [juniper.net] for more information.

Resolved In: junos:23.2R2-S2 junos:23.4R2-S1 junos:24.1R1 junos:24.2R1
1783757
Major
Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion (CVE-2024-47497)
Product-Group=junos
An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88124 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S7 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.

Resolved In: junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:21.2R3-S5-J49 junos:21.2R3-S9 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1562153
Major
Junos OS: Multiple vulnerabilities in cURL resolved
Product-Group=junos
Multiple vulnerabilities have been resolved in Juniper Networks Junos OS by updating cURL third party software. Please refer to https://kb.juniper.net/JSA11207 [juniper.net] for more information.

Resolved In: evo:20.1R3-EVO evo:20.4R2-EVO evo:20.4X50-EVO evo:21.1R1-EVO junos:15.1R7-S9 junos:17.3R3-S12 junos:17.4R3-S5 junos:18.1R3-S13 junos:18.2X75-D34 junos:18.2X75-D55 junos:18.2X75-D61 junos:18.2X75-D68 junos:18.3R3-S5 junos:18.4R2-S9 junos:18.4R3-S9 junos:19.1R3-S5 junos:19.2R1-S7 junos:19.2R3-S2 junos:19.3R2-S6 junos:19.3R2-S7 junos:19.3R3-S2 junos:19.4R1-S4 junos:19.4R2-S4 junos:19.4R3-S3 junos:19.4R3-S5 junos:20.1R2-S2 junos:20.1R3 junos:20.2R2-S3 junos:20.2R3 junos:20.3R2 junos:20.3R3 junos:20.3X75-D10 junos:20.3X75-D20 junos:20.4R1-S1 junos:20.4R2 junos:21.1R1 junos:21.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1562319
Major
The CLI command "show | display rfc5952" may not work on all ipv6 addresses for configuration
Product-Group=junos
IPv6 address incorrectly extracted from export buffer.

Resolved In: evo:20.4R3-S3-EVO evo:21.2R1-J3-EVO evo:21.2R2-S1-EVO evo:21.2R3-EVO evo:21.3R2-EVO evo:21.3R3-EVO evo:21.4R1-S1-EVO evo:21.4R2-EVO evo:22.1R1-EVO junos:20.4R3-S2 junos:21.1R3-S1 junos:21.2R2-S2 junos:21.2R3 junos:21.3R2 junos:21.3R3 junos:21.4R1-S1 junos:21.4R2 junos:21.4R2-S1 junos:22.1R1
1645119
Critical
Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=junos
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/JSA82992 [juniper.net] for more information.

Resolved In: evo:21.4X9-EVO evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R1-S1-EVO evo:22.3R2-EVO evo:22.3X80-D47-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S10 junos:21.4R3-S9 junos:22.1R2-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S1 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1 junos:23.2R2-S1



Modification History

First publication 2025-03-20