Following vulnerabilities in OpenSSL software included with ScreenOS have been addressed in ScreenOS 6.3.0 r22:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
The following software releases have been updated to resolve this specific issue: ScreenOS 6.3.0 r22 (released April 6, 2016) and all subsequent releases. These issues are being tracked as PR 1100194 and 1144749 and are visible on the Customer Support website.
How to obtain fixed software: Software release Service Packages are available at http://support.juniper.net from the "Download Software" links. Select your appropriate Selected Products, or browse by Series or Technology, once you find the appropriate fixed version(s) for your needed platform download and apply the updated version(s) of choice.
Methods to reduce the risk associated with this issue include:
2016-04-13: Initial publication 2016-04-14: Updated workaround section