Vulnerabilities > CVE-2013-6958 - Unspecified vulnerability in Juniper Netscreen-5200, Netscreen-5400 and Screenos
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN juniper
nessus
Summary
Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 | |
Hardware | 2 |
Nessus
NASL family | Firewalls |
NASL id | SCREENOS_JSA10604.NASL |
description | The remote host is running a version of Juniper ScreenOS prior to 5.4.0r28 / 6.2.0r18 / 6.3.0r16. It is, therefore, affected by a denial of service vulnerability due to a failure to properly handle ICMP echo request packets. A remote, unauthenticated attacker could potentially exploit this vulnerability by sending malformed ICMP echo request packets to cause a firewall crash or failover. Repeated exploitation can result in an extended denial of service condition. Note that the host is not affected if the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 74367 |
published | 2014-06-06 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/74367 |
title | Juniper ScreenOS 5.4 < 5.4.0r28 / 6.2 < 6.2.0r18 / 6.3 < 6.3.0r16 Malformed ICMP Echo Request DoS (JSA10604) |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 64260 CVE(CAN) ID: CVE-2013-6958 ScreenOS是Netscreen防火墙安全解决方案所使用的操作系统。 ScreenOS 5.4, 6.2.0, 6.3.0版本中禁用了"Ping of Death"屏幕后,处理特制报文的实现上存在安全漏洞,成功利用后可导致拒绝服务。 0 Juniper Networks ScreenOS 6.3 Juniper Networks ScreenOS 6.2 厂商补丁: Juniper Networks ---------------- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://kb.juniper.net/InfoCenter https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10604 |
id | SSV:61109 |
last seen | 2017-11-19 |
modified | 2013-12-13 |
published | 2013-12-13 |
reporter | Root |
title | Juniper Networks ScreenOS 拒绝服务漏洞 |
References
- http://jvn.jp/en/jp/JVN28436508/index.html
- http://jvn.jp/en/jp/JVN28436508/index.html
- http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000119.html
- http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000119.html
- http://osvdb.org/100861
- http://osvdb.org/100861
- http://www.securitytracker.com/id/1029490
- http://www.securitytracker.com/id/1029490
- https://kb.juniper.net/JSA10604
- https://kb.juniper.net/JSA10604