Junos Local Patch Checking Support Added to Nessus
by Paul Asadoorian on August 29, 2011
Tenable has authored a collection of plugins to identify Juniper Junos devices and perform local patch checking. By providing SSH or SNMP credentials, Nessus will log into a device running Junos and check for missing patches, such as:
- Junos J-Web Weak SSL Ciphers (PSN-2011-01-147)
- Junos debug.php Unauthenticated Debug Access (PSN-2011-02-158)
- Junos 11.1R1 on EX Series Switches Causes Multiple sfid Daemon Crashes (PSN-2011-04-241)
- Junos PIM rpd DoS (PSN-2011-07-296)
- Junos ICMP Ping 'Composite Next-Hop' DoS (PSN-2011-07-297)
- Junos Fragmented ICMP Packets DoS (PSN-2011-07-298)
- Junos IPv6 Over IPv4 Security Policy Bypass (PSN-2011-07-299)
- Junos DHCP Relay Agent Traffic Redirection (PSN-2011-07-300)
You can enable these plugins by selecting the "Junos Local Security Checks" plugin family when creating policies in Nessus (or SecurityCenter) as shown below:
Plugin ID 55392, Junos Version Detection, was added to identify the operating system version of the device being scanned: