Lucene search

K
cve[email protected]CVE-2014-0616
HistoryJan 15, 2014 - 4:08 p.m.

CVE-2014-0616

2014-01-1516:08:04
CWE-362
web.nvd.nist.gov
21
cve-2014-0616
juniper junos
denial of service
remote attack
bgp
rdp crash
security vulnerability

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%

Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R4-S2, 13.1 before 13.1R3-S1, 13.2 before 13.2R2, and 13.3 before 13.3R1 allows remote attackers to cause a denial of service (rdp crash) via a large BGP UPDATE message which immediately triggers a withdraw message to be sent, as demonstrated by a long AS_PATH and a large number of BGP Communities.

Affected configurations

NVD
Node
juniperjunosMatch10.4
OR
juniperjunosMatch11.4
OR
juniperjunosMatch12.1r
OR
juniperjunosMatch12.1x44
OR
juniperjunosMatch12.1x45
OR
juniperjunosMatch12.1x46
OR
juniperjunosMatch12.2
OR
juniperjunosMatch12.3
OR
juniperjunosMatch13.1
OR
juniperjunosMatch13.2
OR
juniperjunosMatch13.3

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%

Related for CVE-2014-0616