HomeinetMalicious code in Juniper firewalls

Malicious code in Juniper firewalls

You may not know exactly what Juniper does, but you may have already used its products to surf the internet without even knowing it.

Juniper manufactures network hardware (like Cisco) and is used by corporate infrastructures around the world.

The company admitted today (source: TNW) that at some point in the past, it discovered malicious code in its ScreenOS firmware used by NetScreen devices. The malicious code could allow a hacker or government agency to gain administrative access to devices, as well as decrypt VPN connections.juniper

NetScreen was acquired by Juniper in 2004, as it looked to strengthen networks and their security. Many of the company's products inspect data packets, such as network traffic to detect malicious intent before it reaches end users.

So even if Juniper tries to downplay the fact, things are very serious.

The fact that the company says it doesn't know – or doesn't admit to knowing – who added the malicious code is a very serious cause for concern, given that it could have been there for years before being detected.

Considering the NSA's active spying programs, it is easy to connect the attack to the agency's FEEDTROUGH program that targeted the company's firewalls.

The company has not made any further statements at this time, but according to the article it published, it admits that "there is no way to detect that this vulnerability was exploited" and that it could lead to a "complete breach" of the affected system.

The company has released a patch for the vulnerability in NetScreen devices. But since there is no way to detect the attack, who knows if the problem has been fixed?

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS