Lucene search

K
cve[email protected]CVE-2014-6382
HistoryJan 16, 2015 - 4:59 p.m.

CVE-2014-6382

2015-01-1616:59:02
CWE-20
web.nvd.nist.gov
19
cve-2014-6382
juniper
mx series routers
junos
denial of service
bbe router
pppoe discovery
lcp phase

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.

Affected configurations

NVD
Node
juniperjunosMatch13.3r3
OR
juniperjunosMatch13.3r4
OR
juniperjunosMatch13.3r5
OR
juniperjunosMatch14.1
OR
juniperjunosMatch14.1r1
OR
juniperjunosMatch14.1r2
OR
juniperjunosMatch14.1r3
OR
juniperjunosMatch14.2
OR
juniperjunosMatch14.2r1
AND
junipermx10
OR
junipermx104
OR
junipermx2010
OR
junipermx2020
OR
junipermx240
OR
junipermx40
OR
junipermx480
OR
junipermx80
OR
junipermx960
OR
junipervmx

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

Related for CVE-2014-6382