On SRX Series services gateways, when plugins that use TCP proxy are configured (e.g. ALGs, UTM), a certain sequence of valid TCP packets may cause the flow daemon (flowd) to crash. Repeated crashes of flowd can represent an extended denial of service condition for the gateway. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue. This issue has been assigned CVE-2013-6015.
The following software releases have been updated to resolve this specific issue:
If ALGs and/or UTM features are not required, disabling ALGs and UTM features will mitigate this issue.