First published: Fri May 03 2002(Updated: )
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetScreen ScreenOS | <=2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0234 has a high severity due to its potential to cause denial of service through resource exhaustion.
To fix CVE-2002-0234, upgrade your NetScreen ScreenOS to version 2.6.1 or later.
Users of Juniper NetScreen ScreenOS versions prior to 2.6.1 are affected by CVE-2002-0234.
CVE-2002-0234 facilitates a denial of service attack by allowing resource exhaustion through excessive concurrent sessions.
CVE-2002-0234 is exploitable from a trusted internal network when performing port scans to an external network.