A denial of service (DoS) issue has been discovered in ScreenOS firewalls that can be exploited by remote unauthenticated attackers. When a malformed SSL/TLS protocol packet is sent to a vulnerable ScreenOS firewall, the firewall crashes and restarts or if in a HA configuration triggers a failover. The issue can be repeatedly exploited to create an extended denial of service condition. Older versions of ScreenOS have reached the end of support milestone and have not been evaluated for the issue, but are likely affected. Customers are advised to upgrade to a fixed supported release once it is made available. While Juniper has not seen any malicious exploitation of this vulnerability, the packet has been found in normal network activity. No other Juniper Networks products or platforms are affected by this issue. This issue has been assigned CVE-2014-2842 .
Juniper Networks has released patches and new software to resolve this issue (see the links below): The fix for this issue is found in ScreenOS 6.3.0r17. You can download the software at the following link: http://www.juniper.net/support/downloads/?p=ssg140#sw Patches: NS-5200/5400 M3: https://download.juniper.net/software/firewall/ns5000.6.3.0-M3A.r16a-dfj1.0 NS-5200/5400 M2: https://download.juniper.net/software/firewall/ns5000.6.3.0-M2A.r16a-dfj1.0 ISG-2000 with IDP: https://download.juniper.net/software/firewall/nsISG2000.6.3.0-IDP1.r16a-dfj1.0 ISG-2000: https://download.juniper.net/software/firewall/nsISG2000.6.3.0r16a-dfj1.0 ISG-1000 with IDP: https://download.juniper.net/software/firewall/nsISG1000.6.3.0-IDP1.r16a-dfj1.0 ISG-1000: https://download.juniper.net/software/firewall/nsISG1000.6.3.0r16a-dfj1.0 SSG-520/SSG-550: https://download.juniper.net/software/firewall/ssg500.6.3.0r16a-dfj1.0 SSG-320/SSG-350: https://download.juniper.net/software/firewall/ssg320ssg350.6.3.0r16a-dfj1.0 SSG-140: https://download.juniper.net/software/firewall/ssg140.6.3.0r16a-dfj1.0 SSG-5/20: https://download.juniper.net/software/firewall/ssg5ssg20.6.3.0r16a-dfj1.0 KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
Due to the likelihood of the specific packet occurring during normal activity, Juniper recommends disabling WebUI (SSL) and WebAuth (SSL) until a software fix is available. This includes disabling WebUI (SSL) and WebAuth (SSL) even on internal and protected networks. This issue is completely mitigated when WebUI (SSL) and WebAuth (SSL) is disabled. Disabling SSL WebUI (HTTPS) is part of our best practices, as mentioned in KB29016 [juniper.net] .