Description

The BugSec Group and Cynet published an article​  on Dec 9 2015 about a firewall bypass vulnerability in some Next Generation Firewalls. This vulnerability may allow data exfiltration to destinations forbidden by firewall policies. This is also known as the  FireStorm vulnerability .​

Such a firewall bypass is not possible on Juniper's SRX and ScreenOS firewalls. Neither ScreenOS nor SRX will send packets to destinations that are forbidden by policy.

Our IDP and App-Secure (available on SRX) processing happens on top of normal policy processing. Normal policy processing is not relaxed in any way to allow IDP or App-Secure features. If security policies are properly setup, connections to forbidden destinations as described in the FireStorm article are not possible through SRX and ScreenOS firewalls.

ScreenOS and SRX provide another feature called strict-syn-checking to restrict packets during TCP 3-way handshake to prevent any packets until the 3-way handshake has completed for the connection that was allowed by security policies.

Additionally, when strict TCP SYN check option is enabled on SRX series devices, TCP handshake packets with extra data are dropped.

See KB4444 [juniper.net] for more information about TCP SYN check option in ScreenOS.

See KB21266 [juniper.net] for more information about TCP SYN check option in Junos.

Solution

Juniper Networks firewall products are not vulnerable to this firewall bypass vulnerability.

Related Information