![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.105914 |
Category: | JunOS Local Security Checks |
Title: | Juniper Networks Junos OS SIP ALG Denial of Service Vulnerability |
Summary: | DoS on SRX devices when SIP ALG is enabled |
Description: | Summary: DoS on SRX devices when SIP ALG is enabled Vulnerability Insight: On SRX Series devices, when SIP ALG is enabled, a certain crafted SIP packet may cause the flowd process to crash. SIP ALG is enabled by default on SRX Series devices except for SRX-HE devices. SRX-HE devices have SIP ALG disabled by default. The status of ALGs can beobtained by executing the 'show security alg status' CLI command. Vulnerability Impact: Repeated crashes of the flowd process constitutes an extended denial of service condition for the SRX Series device. Affected Software/OS: Junos OS 12.1X46 and 12.1X47 Solution: New builds of Junos OS software are available from Juniper. As a workaround disable SIP ALG or enable flow-based processing for IPv6 traffic. CVSS Score: 7.8 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-3815 BugTraq ID: 68551 http://www.securityfocus.com/bid/68551 http://www.securitytracker.com/id/1030557 |
Copyright | Copyright (C) 2014 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |