NetScreen ScreenOS Loss of Configuration Vulnerability
BID:7042
Info
NetScreen ScreenOS Loss of Configuration Vulnerability
| Bugtraq ID: | 7042 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2003 12:00AM |
| Updated: | Mar 07 2003 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
NetScreen ScreenOS 4.0.2 NetScreen ScreenOS 4.0.1 NetScreen ScreenOS 4.0 -DIAL NetScreen ScreenOS 4.0 |
| Not Vulnerable: | |
Discussion
NetScreen ScreenOS Loss of Configuration Vulnerability
It has been reported that under certain conditions NetScreen devices running ScreenOS 4.0.0 or later may lose their configurations. Under periods of exceptional load, the devices may revert to factory default settings. This causes all incoming traffic to be rejected and prevents any outgoing traffic since the device loses its default route.
In addition, if the default settings are considered insecure, this condition may result in an exposure.
It has been reported that under certain conditions NetScreen devices running ScreenOS 4.0.0 or later may lose their configurations. Under periods of exceptional load, the devices may revert to factory default settings. This causes all incoming traffic to be rejected and prevents any outgoing traffic since the device loses its default route.
In addition, if the default settings are considered insecure, this condition may result in an exposure.
Exploit / POC
NetScreen ScreenOS Loss of Configuration Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NetScreen ScreenOS Loss of Configuration Vulnerability
Solution:
Maintenance releases are available which address this issue.
Maintenance release r11 addresses NetScreen-5XP/NetScreen-5XT 4.0.
Maintenance release r3 addresses NetScreen-5XT 4.0.0-DIAL.
Maintenance release r4 addresses NetScreen-5XP/NetScreen-5XT 4.1.
Maintenance release r3 addresses NetScreen-5XP/NetScreen-5XT 4.2.
Users should contact the vendor for details on obtaining these maintenance releases.
Solution:
Maintenance releases are available which address this issue.
Maintenance release r11 addresses NetScreen-5XP/NetScreen-5XT 4.0.
Maintenance release r3 addresses NetScreen-5XT 4.0.0-DIAL.
Maintenance release r4 addresses NetScreen-5XP/NetScreen-5XT 4.1.
Maintenance release r3 addresses NetScreen-5XP/NetScreen-5XT 4.2.
Users should contact the vendor for details on obtaining these maintenance releases.
References
NetScreen ScreenOS Loss of Configuration Vulnerability
References:
References:
- NetScreen Security Alert 56305 (NetScreen)