Knowledge Search


2014-06 Security Bulletin: NetScreen Firewall: DNS lookup issue may cause denial of service (CVE-2014-3813)

  [JSA10631] Show KB Properties

  [JSA10631] Hide KB Properties

Security Advisories ID: JSA10631
Last Updated: 11 Jun 2014
Version: 3.0

Product Affected:
NetScreen Firewalls

A Denial of Service (DoS) issue has been found in Juniper Networks NetScreen Firewall products. When encountered, this issue can cause the device to crash and reboot. If an attacker were to repeatedly exploit the issue a sustained denial of service could take place on the device. The issue is not encountered unless a feature is enabled that requires the device to use its built-in DNS lookup client.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue has been assigned CVE-2014-3813

 A software update for ScreenOS has been released to resolve this issue. The release containing the fix includes ScreenOS 6.3r17 and subsequent releases

KB16765 - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.

 There is no workaround for this issue. An upgrade to a fixed version of the software for the fix.


Related Links:

CVSS Score:
7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Risk Level:


Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.