NetScreen ScreenOS Port Scan DoS Vulnerability
BID:4015
Info
NetScreen ScreenOS Port Scan DoS Vulnerability
| Bugtraq ID: | 4015 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0234 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 01 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered by Chris Lathem <[email protected]>. |
| Vulnerable: |
NetScreen ScreenOS 2.6.1 |
| Not Vulnerable: |
NetScreen ScreenOS 3.1 r1 NetScreen ScreenOS 3.1 NetScreen ScreenOS 3.0.1 r1 NetScreen ScreenOS 3.0 r1 NetScreen ScreenOS 2.8 r1 NetScreen ScreenOS 2.6.1 r2 Netscape FastTrack Server 3.0.0r1 |
Discussion
NetScreen ScreenOS Port Scan DoS Vulnerability
NetScreen is a line of Internet security appliances integrating firewall, VPN and traffic management features. ScreenOS is the software used to manage and configure the firewall. NetScreen supports Microsoft Windows 95, 98, ME, NT and 2000 clients.
An issue has been reported in NetScreen ScreenOS which could cause the system to stop responding.
If a user within the trusted network attempts to do a port scan on an external system, ScreenOS could fail requiring a restart. This is due to the number of concurrent sessions allowed per user.
Exploitation of this issue is possible using a port scanner that does not properly release sessions.
NetScreen is a line of Internet security appliances integrating firewall, VPN and traffic management features. ScreenOS is the software used to manage and configure the firewall. NetScreen supports Microsoft Windows 95, 98, ME, NT and 2000 clients.
An issue has been reported in NetScreen ScreenOS which could cause the system to stop responding.
If a user within the trusted network attempts to do a port scan on an external system, ScreenOS could fail requiring a restart. This is due to the number of concurrent sessions allowed per user.
Exploitation of this issue is possible using a port scanner that does not properly release sessions.
Exploit / POC
NetScreen ScreenOS Port Scan DoS Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
NetScreen ScreenOS Port Scan DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.