Please review the following Juniper Security Alerts to determine if you may be impacted: JSA10712 [juniper.net] - 2015-12 Out of Cycle Security Bulletin: ScreenOS: Crafted SSH negotiation may trigger system crash (CVE-2015-7754) http://kb.juniper.net/JSA10712 [juniper.net] . JSA10713 [juniper.net] - 2015-12 Out of Cycle Security Bulletin: ScreenOS: Multiple Security issues with ScreenOS (CVE-2015-7755) http://kb.juniper.net/JSA10713 [juniper.net] . NOTE : JSA10713 [juniper.net] has been updated to provide more specific details on which release is affected by a known vulnerability identified in the alert. If you are running an affected release, please read this document in it’s entirely to ensure a successful upgrade.
RECOMMENDED SOFTWARE UPGRADE: <o:p>
Affected Release <o:p>
Recommended Release (select version to download) <o:p>
6.2.0 <o:p>
<o:p>
6.2.0r15
6.2.0r19
6.2.0r16
6.2.0r17
6.2.0r18
6.3.0 <o:p>
6.3.0r12
6.3.0r12b
6.3.0r13
6.3.0r13b
6.3.0r14
6.3.0r14b
6.3.0r15
6.3.0r15b
6.3.0r16
6.3.0r16b
6.3.0r17
6.3.0r17b
6.3.0r18
6.3.0r18b
6.3.0r19
6.3.0r19b
6.3.0r20
6.3.0r21
<o:p> Juniper recommends updating to the latest software. However to have minimal affect on the network you should upgrade to a equivalent software version while you qualify the latest version of ScreenOS.
Recommended releases are available for download from Juniper Network’s Download Software page . If you experience issues downloading the recommended release, please Contact Support for assistance .
VERIFY IMAGE AUTHENTICATION KEY PRIOR TO UPGRADE: <o:p>
PRIOR TO UPGRADING YOUR SCREENOS RELEASE, PLEASE CONFIRM THAT YOU HAVE THE REQUISITE IMAGE KEY INSTALLED. FAILURE TO UPDATE TO THE CURRENT KEY IMAGE WILL RESULT IN UPGRADE FAILURE. <o:p>