Overview
Juniper ScreenOS 6.3, and possibly earlier versions, is vulnerable to a denial of service from malformed SSL packets.
Description
Juniper ScreenOS 6.3, and possibly earlier versions, is vulnerable to a denial of service from malformed SSL packets. Additional details may be found in Juniper security advisory JSA10624. |
Impact
A remote unauthenticated attacker may be able to produce an extended denial of service against a ScreenOS firewall by repeatedly sending malformed SSL/TLS packets to the device. |
Solution
Juniper security advisory JSA10624 recommends the following workaround. |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| Temporal | 6.8 | E:H/RL:OF/RC:C |
| Environmental | 6.8 | CDP:LM/TD:M/CR:L/IR:L/AR:H |
References
Acknowledgements
Thanks to David Klein of DHK Enterprises for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
| CVE IDs: | CVE-2014-2842 |
| Date Public: | 2014-04-16 |
| Date First Published: | 2014-05-16 |
| Date Last Updated: | 2014-05-16 15:05 UTC |
| Document Revision: | 12 |