A DNS server can be tricked into accepting and caching incorrect translations of network names. A malicious user can use this vulnerability to "hijack" the target, redirecting all accesses to a substitute network host or service. DNS servers that cache the incorrect results will continue to redirect all clients to the substitute host or service indefinitely. This vulnerability is tracked by CERT/CC as VU#800113.
Juniper Networks has modified several of its software products to include improved DNS forgery resilience mechanisms as suggested by Internet drafts and other sources. Consult the following table to determine if your Juniper Networks product is susceptible to this vulnerability and what action is required to remedy the issue.
Customers running vulnerable products are strongly urged to take the appropriate steps identified in the above table. Where a software upgrade is required or recommended, please visit the Juniper Networks Customer Support web-site at http://www.juniper.net/customers/support/ or contact the Juniper Networks Technical Assistance Center (JTAC).
2017-03-05: Category restructure.