Juniper Junos OpenSSL Heartbeat Information Disclosure (JSA10623) (Heartbleed)
High Nessus Plugin ID 73687
The remote device is missing a vendor-supplied security patch.
According to its self-reported version number, the remote Junos device is affected by an information disclosure vulnerability. An out-of-bounds read error, known as Heartbleed, exists in the TLS/DTLS implementation due to improper handling of TLS heartbeat extension packets. A remote attacker, using crafted packets, can trigger a buffer over-read, resulting in the disclosure of up to 64KB of process memory, which contains sensitive information such as primary key material, secondary key material, and other protected content. Note that this issue only affects devices with J-Web or the SSL service for JUNOScript enabled.
Apply the relevant Junos software release or workaround referenced in Juniper advisory JSA10623.