Juniper NetScreen Security Manager (NSM) guiSrv/devSrv Crafted String Remote DoS

This script is Copyright (C) 2006-2011 Tenable Network Security, Inc.


Synopsis :

The remote server is affected by a remote denial of service flaw.

Description :

The version of Juniper NetScreen-Security Manager (NSM) installed on
the remote host may allow an attacker to deny service to legitimate
users using specially crafted long strings to the guiSrv and devSrv
processes. A watchdog service included in Juniper NSM, though,
automatically restarts the application.

By repeatedly sending a malformed request, an attacker may permanently
deny access to legitimate users.

See also :

http://archives.neohapsis.com/archives/fulldisclosure/2005-12/1281.html
http://www.juniper.net/customers/support/products/nsm.jsp

Solution :

Upgrade to Juniper NSM version 2005.1

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.6
(CVSS2#E:U/RL:U/RC:C)
Public Exploit Available : false

Family: Firewalls

Nessus Plugin ID: 20388 ()

Bugtraq ID: 16075

CVE ID: CVE-2005-4587