Overview
Juniper ScreenOS 6.3, and possibly earlier versions, is vulnerable to a denial of service from malformed SSL packets.
Description
Juniper ScreenOS 6.3, and possibly earlier versions, is vulnerable to a denial of service from malformed SSL packets. Additional details may be found in Juniper security advisory JSA10624. |
Impact
A remote unauthenticated attacker may be able to produce an extended denial of service against a ScreenOS firewall by repeatedly sending malformed SSL/TLS packets to the device. |
Solution
Juniper security advisory JSA10624 recommends the following workaround. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Temporal | 6.8 | E:H/RL:OF/RC:C |
Environmental | 6.8 | CDP:LM/TD:M/CR:L/IR:L/AR:H |
References
Acknowledgements
Thanks to David Klein of DHK Enterprises for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2014-2842 |
Date Public: | 2014-04-16 |
Date First Published: | 2014-05-16 |
Date Last Updated: | 2014-05-16 15:05 UTC |
Document Revision: | 12 |