Juniper Networks has issued a statement regarding suspicious code found in its ScreenOS software.
Posted by SVP of IT Bob Worrall, Juniper said that during a recent internal code review, it discovered unauthorized code in ScreenOS that could allow a skilled attacker to gain administrator access to NetScreen devices. This would allow decryption of VPN.
"Since we identified these vulnerabilities, we have initiated an investigation into the issue and worked to develop and release updates for the latest versions of ScreenOS," he said.
“At this time, we have not received any reports of these vulnerabilities. However, we recommend that customers update their systems and apply the highest priority updates.”
Juniper claimed that there were two independent issues involving the unauthorized code: the first issue allows unauthorized remote access with administrator privileges to the device via SSH or telnet and exploiting the vulnerability could put the affected system at great risk. The second issue could allow a skilled attacker who can monitor VPN traffic to decrypt the traffic.
No other devices running Junos are currently affected, and the company said that all devices running NetScreen ScreenOS versions 6.2.0r15 through 6.2.0r18, and 6.3.0r12 through 6.3.0r20 are affected by these issues and require a fix.
Security researcher “The Grugq” pointed out that the backdoor has existed since late 2012 and can only be fixed by upgrading to the new version of the software.

