← Vulnerability feed

Vulnerability record · CVE-2014-2842 · published 15 April 2014

CVE-2014-2842: Juniper screenos vulnerability

Juniper · Screenos

Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.

7.8 CVSS 2.0 High EPSS 3.5% · top 11.3% CWE-399 · CWE-399
7.8CVSS 2.0 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2842 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7755Juniper ScreenOS improper authentication grants admin accessJuniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants adm…KEVEPSS 61%analysed8.1CVE-2015-7754Juniper screenos improper input validation vulnerabilityJuniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or exec…EPSS 3.9%7.8CVE-2014-3813Juniper screenos vulnerabilityUnspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lo…EPSS 1.3%7.8CVE-2014-3814Juniper screenos improper input validation vulnerabilityThe Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote att…EPSS 1.3%7.5CVE-2016-1268Juniper screenos improper input validation vulnerabilityThe administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra…EPSS 1.9%7.1CVE-2013-6958Juniper screenos vulnerabilityJuniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of…EPSS 1.9%6.5CVE-2018-0014Juniper screenos information exposure vulnerabilityJuniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from p…EPSS 0.60%5.4CVE-2017-2337Juniper screenos cross-site scripting vulnerabilityA persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2014-2842), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.