Multiple traffic classification vulnerabilities in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when ' no-syn-check' is enabled on the device. In one case, JDPI incorrectly classifies out-of-state asymmetric TCP flows as the dynamic-application INCONCLUSIVE instead of UNKNOWN, which is more permissive. A second issue was discovered where the dynamic-application classification is not properly provided to the policy module and hence traffic continues to use the pre-id-default-policy. In both cases, without the combination of fixes, the firewall allows traffic to be forwarded that should have been denied. causing the firewall to allow traffic to be forwarded that should have been denied.
no-syn-check'
These issues only occur when ' set security flow tcp-session no-syn-check ' is configured on the device.
set security flow tcp-session no-syn-check
One or more of these issues affect Juniper Networks Junos OS on SRX Series:
These issues do not affect Juniper Networks Junos OS versions prior to 18.4R1.
These issues will only be seen when the following configuration is present:
[security flow tcp-session no-syn-check]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
These issues were seen during production usage.
The following issues have been reported and resolved:
The following software releases have been updated to resolve both issues: Junos OS 18.4R2-S10, 18.4R3-S10, 19.1R3-S8, 19.2R1-S8, 19.2R3-S4, 19.3R3-S3, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R2-S2, 20.4R3, 21.1R2-S2, 21.1R3, 21.2R2, 21.3R1, and all subsequent releases.
Notes:
Both PRs are resolved in the releases listed above.
These issues are being tracked as 1561533 and 1599053 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
Either of the following workarounds will mitigate these issues:
security flow tcp-session no-syn-check
set services application-identification application-system-cache security-services
2022-01-12: Initial Publication.