QID 44030

Date Published: 2023-05-30

QID 44030: Juniper Network Operating System (Junos OS) Multiple NTP Vulnerabilities (JSA11171)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

Multiple NTP vulnerabilities have been resolved in Juniper Networks Junos OS and Junos OS Evolved by updating third party software where vulnerabilities were found during external security research.

Affected Junos versions:
Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15 on EX Series
12.3X48 versions prior to 12.3X48-D95 on SRX Series
14.1X53 versions prior to 14.1X53-D53
15.1 versions prior to 15.1R7-S6 on EX Series
15.1X49 versions prior to 15.1X49-D190 on SRX Series
16.1 versions prior to 16.1R7-S6
16.2 versions prior to 16.2R3
17.1 versions prior to 17.1R2-S11, 17.1R3-S1
17.2 versions prior to 17.2R1-S9, 17.2R2-S8, 17.2R3-S3
17.3 versions prior to 17.3R2-S5, 17.3R3-S6
17.4 versions prior to 17.4R2-S7, 17.4R3
18.1 versions prior to 18.1R3-S8
18.2 versions prior to 18.2R2-S7, 18.2R3-S1
18.3 versions prior to 18.3R1-S5, 18.3R2-S2, 18.3R3
18.4 versions prior to 18.4R1-S4, 18.4R2-S1, 18.4R3
19.1 versions prior to 19.1R1-S3, 19.1R2
19.2 versions prior to 19.2R1-S1, 19.2R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.

Note: This QID does not checks for only affected versions hence set to practice.

Successful exploitation of these vulnerabilities could lead to addition or modification of data, or Denial of Service (DoS).

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Please refer JSA11171

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    JSA11171 URL Logo supportportal.juniper.net/s/article/2021-04-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Multiple-NTP-vulnerabilities-resolved?language=en_US