Juniper Junos OpenSSL Heartbeat Information Disclosure (JSA10623) (Heartbleed)

High Nessus Plugin ID 73687


The remote device is missing a vendor-supplied security patch.


According to its self-reported version number, the remote Junos device is affected by an information disclosure vulnerability. An out-of-bounds read error, known as Heartbleed, exists in the TLS/DTLS implementation due to improper handling of TLS heartbeat extension packets. A remote attacker, using crafted packets, can trigger a buffer over-read, resulting in the disclosure of up to 64KB of process memory, which contains sensitive information such as primary key material, secondary key material, and other protected content.

Note that this issue only affects devices with J-Web or the SSL service for JUNOScript enabled.


Apply the relevant Junos software release or workaround referenced in Juniper advisory JSA10623.

See Also

Plugin Details

Severity: High

ID: 73687

File Name: juniper_jsa10623.nasl

Version: 1.13

Type: combined

Published: 2014/04/18

Modified: 2017/05/16

Dependencies: 55932

Risk Information

Risk Factor: High


Base Score: 9.4

Temporal Score: 8.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:juniper:junos

Required KB Items: Host/Juniper/model, Host/Juniper/JUNOS/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/04/11

Vulnerability Publication Date: 2014/02/24

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-0160

BID: 66690

OSVDB: 105465

CERT: 720951

EDB-ID: 32745, 32764, 32791, 32998

JSA: JSA10623